Skip Navigation

06.3 HHS PIA Summary for Posting (Form) / CDC African American Men who have Sex with Men (AAMSM) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: NO

4. Privacy Act System of Records (SOR) Number: NO

5. OMB Information Collection Approval Number: NO

6. Other Identifying Number(s): NO

7. System Name: African American Men who have Sex with Men (AAMSM)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Carolyn Guenther-Grey

10. Provide an overview of the system: The purpose of AAMSM data collection system is to permit funded sites to perform the following activities:

· Manage venue information and venue testing activities for alternate venue testing and targeted outreach strategies

· Manage interview data and other information about at-risk individuals who are nominated via the social networks and PCRS strategies

· Manage clients’ demographic, HIV risk, HIV CTR, and strategy-specific information

· Manage time and cost information collected for each strategy

· Manage project staff details (e.g., time spent on a specific strategy activity, hourly rate)

· Generate custom reports that summarize project data (by and across strategies) and facilitate effective program monitoring and evaluation

The desired impact of this project is to improve the public's health by reducing the number of new HIV infections occurring each year in the United States. The goals of this project are to increase the proportion of HIV-infected African American MSM in the U.S. who are aware of their status and linked to appropriate prevention, care and treatment services. To accomplish these goals, project staff and grantees will evaluate the relative effectiveness of testing strategies based on existing models (e.g., mobile testing and alternative venue testing to make testing more accessible, using social networks of HIV-infected persons to refer at-risk peers for testing, and partner counseling and referral services). This project supports the following CDC Health Protection goal: Healthy People in Every Stage of Life. Although this project can potentially impact people in all life stages, the focus of the project is on improving the health of adults. The target population is 18 – 24 year old African American MSM. AAMSM will continue from 6/2008 until 10/2010.

13. Indicate if the system is new or an existing one being modified:

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The funded grantees will collect and maintain the following information

· Venue information and venue testing activities for alternate venue testing strategy

· Interview data and other information about at-risk individuals who are nominated via the social networks and PCRS strategies

· Clients’ demographic, HIV risk, HIV CTR, and strategy-specific information

· Manage time and cost information collected for each strategy

· Project staff details for the staff who are involved in various activities of the project (e.g., time spent on a specific strategy activity, hourly rate)

The information collected at the sites will be sent to the CDC via secure data network (SDN) for analyzing the data collected.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NO

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. HarrisSr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 28, 2008

Date Published: Sept 8. 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCCHIS NCPHI DEOC Request System (DRS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-1255-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DEOC Request System (DRS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kim Hinton

10. Provide an overview of the system: This system is used by the CDC Emergency Operations Center to manage and track tasks that come into the Operations Center.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system does not share or disclose IIF.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Name and phone numbers are collected. They are used to assign a point of contact for the tasks. A person may be contacted if there are any questions about a given task.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The information is not disseminated.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: CDC EMSSP security controls are adequate to protect the IIF contained within this system. The controls ensure a common baseline level of protection is met for all CDC information systems.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 28, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCEHIP ATSDR Hazardous Substances Emergency Event System - (HSEES) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-9221-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: HSEES (Hazardous Substances Emergency Events Surveillance)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Maureen Orr

10. Provide an overview of the system: The Hazardous Substances Emergency Events Surveillance (HSEES) system was established by ATSDR to collect and analyze information about acute releases of hazardous substances, as well as threatened releases that result in a public health action such as an evacuation. The goal of HSEES is to reduce the morbidity (injury) and mortality (death) that result from hazardous substances events, which are experienced by first responders, employees, and the general public.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The Hazardous Substances Emergency Event Surveillance application collects company name and address information on the event location and the parties responsible for hazardous chemical events. Addresses of individuals (private households) are also collected, but not their names. The application also collects name (government employee), agency, address, and phone information on the party who notified the state department of the event. The address information is used to determine the latitude/ longitude values, and demographics/ proximity information of hazardous events to aid in prevention and outreach. The name of the event location is used to determine the type of industry that was involved with the hazardous release. The notification information is used for contact purposes in case data received is incomplete. User names, states, and email addresses are stored for user roles and privileges.

IIF is only shared or disclosed to HSEES users who are State and International Partners (State Health Departments). Each state can only access their data. DHS users can access data from all states but name, address, and phone fields are encrypted. NOTE: IIF is NOT retrieved by Privacy data.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The Hazardous Substances Emergency Event Surveillance application collects company name and address information on the event location and the parties responsible for hazardous chemical events. Addresses of individuals (private households) are also collected, but not their names. The application also collects name (government employee), agency, address, and phone information on the party who notified the state department of the event. The address information is used to determine the latitude/ longitude values, and demographics/ proximity information of hazardous events to aid in prevention and outreach. The name of the event location is used to determine the type of industry that was involved with the hazardous release. The notification information is used for contact purposes in case data received is incomplete. User names, states, and email addresses are stored for user roles and privileges. The IIF collected in this system is not mandatory.

Data are entered by participating state health departments into a web-based application that enables ATSDR to instantly access data for analysis.

Data collected include the following:

• Name, address, and phone # of the source that notified the state health department of the event and the date of the notification.

• Time, date, and day of the event.

• Geographic location (street, city, county, state, zip, country, latitude, longitude)

• Name of the event location, and the party responsible for the release.

• The type of industry involved

• The proximity and demographic (land use and nearby population information to estimate the number of persons potentially exposed)

• Place within the facility where the event occurred

• Event type (fixed-facility or transportation related event)

• Factors contributing to the release

• The substances released

• Environmental sampling and follow-up health activities

• Specific information on injured persons: age, sex, type and extent of injuries, distance from spill, population group (employee, general public, responders, student), and type of protective equipment used

• Information about decontaminations, orders to evacuate or shelter-in-place

Data are used to:

• Provide presentations of data from HSEES to industries that account for a significant number of spills to help plan prevention strategies

• Provide data for Hazardous Material training courses, including data on the risk of injury from methamphetamine labs

• Provide data to establish and maintain protection areas for municipal water systems

• Provide data by county on spills to assist with the proper placement of Hazardous Material teams and equipment

• Distribute fact sheets on frequently spilled chemicals or chemicals that cause a disproportionate number of injuries, such as chlorine and ammonia

• Distribute newsletters or fact sheets to industry, responder, and environmental groups

• Provide presentations for state and local emergency planners

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Administrative:

Users are assigned unique roles and privileges depending on their titles. The HSEES system administrator is responsible for assigning these roles.

Technical:

Depending on the user’s role certain fields containing IIF data are encrypted. Company name, address, and telephone information are entered by and visible to State users, but are encrypted to the Division of Health Studies (DHS) representatives.

User access and authentication is provided through a Secure Data Network (SDN) issued digital certificate which is valid for one year from the date of receipt. Each user will be assigned a unique numeric token which will be used to access the SDN Web Server and assign user roles and privileges. SDN also requires a passphrase to access the SDN Web Server.

Physical Controls:

Production and test servers are stored in a server room secured by the CDC. Access tools are in place to secure entry into CDC buildings (Guards, ID Badges, Key Card, Cipher Locks, Closed Circuit TV).

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 11, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCEHIP NCEH Pesticide Sample Tracking Analysis and Reporting System - (PSTARS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9623-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Pesticide Sample Tracking, Analysis, and Reporting System (PSTARS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Charles Chambers

10. Provide an overview of the system: Pesticide Sample Tracking, Analysis, and Reporting System (PSTARS) is a form of a Lab Information Management System (LIMS). The system is non-web based and is designed to track samples from receipt through reporting. The samples are received from the National Center for Environment Health (NCEH)/Division of Laboratory Sciences (DLS) Sample Logistics section along with a printout of sample IDs. The sample IDs are then transferred to an Excel spreadsheet for importing to PSTARS. Sample IDs are associated with a Study, Lab Method, and Matrix upon import. Samples are tracked through the laboratory process in PSTARS for creating Runsheets, cleanup, creating an Excel Sequence for importing to the lab instruments, importing Excel spreadsheet result data from lab instruments, and exporting formatted results to a spreadsheet.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: PSTARS does not contain IIF information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: PSTARS does not contain IIF information.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: PSTARS does not contain IIF information.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Yes

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCEHIP NCEH Research Data Center (RDC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 14, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9421-00

4. Privacy Act System of Records (SOR) Number: N\A

5. OMB Information Collection Approval Number: N\A

6. Other Identifying Number(s): N\A

7. System Name: Research Data Center (RDC)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Peter Meyer

10. Provide an overview of the system: The National Center for Health Statistics (NCHS) Research Data Center (RDC) is a research program through which approved data users are provided access to data that are not available through NCHS public use releases. The restricted data files contain information such as lower levels of geography (state, county, or lower), but do not contain direct identifiers (name or social security number). These data elements carry no disclosure risk in isolation but can increase disclosure risk when compiled together. An example would be adding together data elements for race/ethnicity, family structure, occupation, state of residence, and sex. Using these data elements together could add to the make a Black female dentist with five children in South Dakota identifiable. On the other hand a researcher may have a legitimate question that requires the use of these elements together. An example would be estimating the prevalence of hepatitis in dentist by state and race/ethnicity.

In order to reduce the risk of disclosure, access to these data is controlled through a formal proposal review committee that includes RDC staff, representatives from the program that produces the data, and the NCHS Confidentiality Officer. The committee may grant three types of access to these data: 1) Onsite, 2) Remote, and 3) Census RDC. Each of these access methods uses different types of information technology to control what data elements user can access.

The term access is very specific to the operations of the RDC. Researchers may work with the data but they are not permitted remove it from the controlled environment. When the proposed research and analysis are complete, they may take the results of their analysis away from the RDC after it undergoes a disclosure risk avoidance examination by RDC staff. No micro data or data sets are permitted to leave the RDC.

Descriptions of the RDC’s three access methods follow:

· On-site Access:

Researchers may be provided access to sensitive data through the RDC secure laboratory on-site at NCHS. There are two labs that house stand alone computers that are not part of the CDC network and have had all of their media ports disabled. These computers are not part of any internal or external network and do not have access to Internet, email, printers or any other communication devise. When researchers arrive at the RDC they surrender cell phones, PDA’s and any other devise that could be used to copy or transmit data. When researchers have completed their analysis the results and output are subject to disclosure review by the RDC analyst assigned to the project. All approved output are then sent via email to the researcher or provided via some other form of electronic media. Printers are not used to create paper copies of analytic results created in the RDC.

· Remote Access:

ANDRE (Analytical Data Research by Email) is the RDC Remote Access system that supports statistical analytical requests of researchers from academic institutions and other government agencies (Federal, State, and local), etc. via Microsoft Outlook email. It authenticates users, runs a pre-analysis disclosure risk algorithms, executes analytical models, runs post-analysis disclosure risk algorithms, and provides the approved results to the researchers. Output from ANDRE is periodically flag for review by RDC staff analysts. The researchers never get to see the micro data and run their programs against a data set that they specify in their research proposal. The users only see output which is summary or aggregate measures that cannot be used to identify individuals.

Email Server

ANDRE

Processing Computer

· Census RDC Access:

Researchers may access NCHS data through the Census RDC system. Data are transferred through an approved CDC Secure Data Network (SDN) which is located in a secure environment in the NCHS RDC. This is a single purpose file server that is used exclusively to link NCHS and Census. The data are transferred to the Census computing facility in Suitland, MD and then are made available to a terminal at one of the Census RDC. The data are not downloadable or printable from the remote site. The output generated by the analysis is then transferred to NCHS via the SDN and examined by RDC staff for disclosure risk. The approved output is then released to the researcher in an electronic format. This is very similar to the Onsite Access method except the access occurs in a Census RDC.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No IIF shared or disclosed

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Data is unique to the individual project and is not maintained by the RDC beyond the duration of the project. Data in the RDC do not contain IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 28, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCEHIP NCIPC Extramural Tracking System - (NEXT) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jun 19, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-04-00-02-0897-00-402-126

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: NCIPC Extramural Tracking System (NEXT)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Robin Forbes

10. Provide an overview of the system: The NCIPC Extramural Tracking System (NEXT) is a workflow system for tracking the publishing of Funding Opportunity Announcements and the award process for the CDC’s National Center for Injury Prevention and Control (NCIPC).

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system maintains information related to Funding Opportunity Announcements and award processing. The information is used to streamline the publishing and awarding of Funding Opportunity Announcements. The information does not contain IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCHIS NCHS Q Bank (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9421-00

4. Privacy Act System of Records (SOR) Number: 09-20-0164

5. OMB Information Collection Approval Number: 0920-222

6. Other Identifying Number(s): N\A

7. System Name: Q-Bank

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kristen Miller with Aaron Maitland as alternate.

10. Provide an overview of the system: Q-Bank was designed as a unique analytical and research tool for researchers and survey professionals. It contains no personal information or personal identifiable information (no IIF is stored in Q-Bank).

Q-Bank is used by, and receives data and funding from, various government agencies including The Bureau of the Census, The National Institute of Science, The National Science Foundation, The National Cancer Institute, and The Bureau of Labor Statistics, as well as CDC/NCHS. Q-Bank’s development and management is under the direction of a Project Manager, an NCHS Project Officer, and an Inter-Agency Steering Committee. While Q-Bank is in an Operational/Maintenance Phase enhancements and modifications are being made to Q-Bank at the direction of the Inter-Agency Steering Committee and the Project Officer.

The Q-Bank application stores survey questions which have been tested to determine the effectiveness of the question. It also contains the Researchers final report, including findings and recommendations based upon the analysis conducted. Questions are indexed and searchable by some 26 categories and endless combinations. Common terms and a common definition of terms and formats across participating agencies were developed to ensure the integrity, common understanding, and effective categorization of the data. No answers are contained in the data.

Q-Bank consists of three modules; The Q-Bank database which is hosted by NCHS, the Q-Bank GUI which is hosted in the MTDC in Atlanta, and Q-Bank Admin which is hosted in NCHS. Q-Bank was originally developed using Sybase’s database and PowerBuilder products. It was then transitioned to Microsoft SQL Server and .net products at the request of NCHS OIT.

Data elements include:

Survey Title

Survey Year

Evaluation Type

Test Date

Sponsor

Testing Agency

Universe

Mode

Field Mode

Documentation

Global Instructions

Separate Instructions

Target Population

Question Topic

Question Type

Information Type

Index Status

Flash Card

Introductory Text

Sequence Number

Core Question

Response Text

Response Category

Response Error

Where Error Occurs

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NO IIF Stored in Q-Bank

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Q-Bank was designed as a unique analytical and research tool for researchers and survey professionals. It contains no personal information or personal identifiable information (no IIF is stored in Q-Bank).

Q-Bank is used by, and receives data and funding from, various government agencies including The Bureau of the Census, The National Institute of Science, The National Science Foundation, The National Cancer Institute, and The Bureau of Labor Statistics, as well as CDC/NCHS. Q-Bank’s development and management is under the direction of a Project Manager, an NCHS Project Officer, and an Inter-Agency Steering Committee. While Q-Bank is in an Operational/Maintenance Phase enhancements and modifications are being made to Q-Bank at the direction of the Inter-Agency Steering Committee and the Project Officer.

The Q-Bank application stores survey questions which have been tested to determine the effectiveness of the question. It also contains the Researchers final report, including findings and recommendations based upon the analysis conducted. Questions are indexed and searchable by some 26 categories and endless combinations. Common terms and a common definition of terms and formats across participating agencies were developed to ensure the integrity, common understanding, and effective categorization of the data. No answers are contained in the data.

Q-Bank consists of three modules; The Q-Bank database which is hosted by NCHS, the Q-Bank GUI which is hosted in the MTDC in Atlanta, and Q-Bank Admin which is hosted in NCHS. Q-Bank was originally developed using Sybase’s database and PowerBuilder products. It was then transitioned to Microsoft SQL Server and .net products at the request of NCHS OIT.

Data elements include:

Survey Title

Survey Year

Evaluation Type

Test Date

Sponsor

Testing Agency

Universe

Mode

Field Mode

Documentation

Global Instructions

Separate Instructions

Target Population

Question Topic

Question Type

Information Type

Index Status

Flash Card

Introductory Text

Sequence Number

Core Question

Response Text

Response Category

Response Error

Where Error Occurs

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No IIF in Q-Bank

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No IIF in Q-Bank

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: PromoteComments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 26, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCHIS NCHS National Health Interview Survey (NHIS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision: Initial PIA Migration to ProSight

1. Date of this Submission: May 14, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-06-01-1020-02

4. Privacy Act System of Records (SOR) Number: 09-20-0164

5. OMB Information Collection Approval Number: 0920-0214

6. Other Identifying Number(s): N\A

7. System Name: National Health Interview Survey

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Anne Stratton

10. Provide an overview of the system: The National Health Interview Survey (NHIS) is a multi-purpose health survey of the civilian non-military population conducted by the National Center for Health Statistics (NCHS), which has produced annual data since 1957. NHIS data are used to describe the health of the US population, monitor trends in national health objectives, set and evaluate health policies, and perform methodological and epidemiological research on important health issues. Findings are generalizable to the US household population but have also been used to explore issues at the regional and state level. Since 1960, the NCHS has had the objective of producing vital and health statistics for the United States. NCHS has legislative authority under 42 U.S.C. 242k, Section 306(b) of the Public Health Service Act to collect statistics on the extent and nature of illness and disability of the population; environmental, social and other health hazards; determinants of health; health resources; and utilization of health care. The NHIS is a multi-purpose health survey conducted by NCHS in support of this legislative charge. It is the principal source of information on the health of the civilian, non-institutionalized population of the United States. Data from NHIS are used to assess agency and NCHS objectives, and initiatives such as Healthy People. Other strategic goals of NCHS are to increase the quality of the data collected and to make it more timely.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NCHS/OAEHP for National Death Index Matching & AHRQ for MEPS sample. The customers of the NHIS are government agencies (federal, state, and local level), international, national, state and community organizations, private researchers, academia, consumer groups, companies, and health care providers. Examples of federal agencies who are recent customers include: the Centers for Medicare and Medicaid Services, the Environmental Pollution Agency, the Food and Drug Administration, General Accounting Office, National Cancer Institute, the National Institute on Aging, the National Institute for Mental Health, and the Veterans Administration. Many organizations have a vested interest in assuring the success and continuity of the NHIS. These organizations include; the Department of Health and Human Services (DHHS), the Agency for Healthcare Research and Quality (AHRQ), and others such as the Bureau of Census(BoC) and policy makers. Through partnerships with NCHS, other agencies within DHHS are able to piggyback on the NHIS infrastructure, expressing the NHIS as a significant DHHS asset. One example is the collaborative efforts between NCHS/DHIS and other DHHS agencies to collect data on topical public health subjects by fielding NHIS Supplements. The AHRQ follows up with half of the NHIS sample on its Medical Expenditure Panel Survey (MEPS). By NHIS providing the MEPS sample, AHRQ was able to save an estimated eight million dollars on its 1996 reengineering project and continues to save budget by forgoing annual listing and other sampling costs. Sharing a sample also allows for a NHIS/MEPS linkage file which enables users to link persons in the MEPS public use file to the records of the same person in the NHIS data file. This adds the broad array of NHIS information to the more specific MEPS data and allows for broad multivariate analyses. The agency shares the information with the public by posing all cleaned, edited, and de-identified data on the CDC website for public access.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: As the Nation's principal health statistics agency, NCHS is responsible for providing accurate, relevant, and timely data. The NHIS collects information along many different domains including health status, health conditions, health behaviors and risk factors, utilization of and access to healthcare, socio-demographic, and economic data. The data collected contains IIF. Participation in the survey is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: NHIS policy does not permit disclosure rule changes and/or data use changes after the time of data collection and consent. The consent procedures in place for a given year continue to guide the use of the data in subsequent years. Any desired changes in data uses or disclosure must be put in place prior to data collection and apply only to that year's data collection. At no point has any disclosure change or data use change occurred in the NHIS after the time of data collection and consent.

There are three separate points in the NHIS collection process where we notify and obtain consent from individuals regarding the collection of information in identifiable form (IIF) and inform said participants of the usage of this IIF.

First, a written advance letter is mailed to all households selected for the NHIS sample. This letter informs the potential participant that his/her participation is voluntary and that all data collected will be kept strictly confidential in accordance with the prevailing laws. The letter also informs the participant that his/her personal information will only be received by NCHS employees and contractors, the U.S. Census Bureau, and NHIS collaborators and that by law; we cannot release information that could identify the participant and participant’s family to anyone else without the participant’s consent. A copy of the 2007 NHIS Advance Letter is available upon request.

Second, when the interviewer makes contact with the potential respondent, there is a standard consent protocol that the interviewer is required to follow which includes displaying the interviewer’s proper credentials and introducing his or herself as an interviewer for the department of the Census conducting the NHIS. The interviewer is then instructed to hand the respondent a copy of the Advance Letter and allow time for the respondent to read it. After the respondent has read the Advance Letter, the interviewer is then instructed to ask "Do you have any questions about anything (you have read/I have read to you) about the National Health Interview Survey?" Following this, the interviewer is to ask "Are you willing to participate in the survey?" A copy of the 2007 NHIS Interviewer Informed Consent Procedures is available upon request.

Third, in the survey instrument itself, text informing the respondent about the reasons for collecting Social Security Number and Medicare Number is read prior to asking these questions. The respondent is asked specific questions asking permission to link NHIS data with data from other sources. These questions detail what the data will be used for and reiterate to the participant that answering these questions is voluntary. A copy of these linkage questions is included within the 2007 NHIS Permission to Link Questions, which is available upon request.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Administrative Controls: In order to ensure least privilege and accountability, each user name is assigned limited access rights to files and directories at varying levels. The CD's and hard copy printouts of records are stored in locked files or offices when not in use. Technical Controls: User ID, passwords, firewall, encryption. Physical Controls: Guards, Identification badges.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Betsey Dunaway

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden, OCISO

Sign-off Date: Aug 18, 2006

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCCDPHP Pediatric Nutrition Surveillance System - (PEDNSS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 14, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 09-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: 09-37-0024

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Pediatric Nutrition Surveillance System (PedNSS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Karen Dalenius

10. Provide an overview of the system: The PedNSS collects clinic data for children <20 years of age, primarily for children age <5 years, from state, territorial and Indian Tribal Organizations WIC program around the country; logs incoming files and performs extensive editing on the file records; produces data quality reports detailing the results of the edits and transmits those reports back to the contributors; merges the edited data into master files in a SQL Server data warehouse; and produces and publishes statistical reports, graphics/maps based on aggregated data from the data warehouse. Locate a system overview on our website at http://www.cdc.gov/pednss.

We use the term “contributor” to refer to the state and territorial health departments and Indian Tribal Organizations (ITS’s) that submit data to the PedNSS.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system shares IIF only with an original PedNSS contributor when that contributor requests copies of their cleaned and edited files. If non-contributors request PedNSS records, the following fields are stripped from the files: State and Substate, Clinic code, Date of Visit, Date of Birth and ID. If a non-contributor needs one or more of these fields on the PedNSS files, they must obtain written permission from the contributor(s) whose records they are requesting. Identifiers are almost always stripped at the request of contributors. Under FOIA requests, we cannot make sharing of data contingent upon obtaining permission from the contributor. However, FOIA does protect personal privacy interests. Data that are identifiable to a specific individual are protected from disclosure. In the event of a FOIA request for data, we strip the following identifying information from the records prior to distribution to a requesting non-contributor: Clinic Code and Identifier.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory:

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: PedNSS records are submitted by state, territorial, and Indian Tribal Organization WIC programs, Medicaid (EPSDT) programs, and state MCH programs, all of which require informed consents to be signed by participants upon program enrollment.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Access to the PedNSS database is governed through an assigned GP-DN-ro group managed by the NCCDPHP SQL database administrator, Terrine Mathews, with input from our team. This group is limited to Data Systems and Surveillance Team members and about eight DNPAO epidemiologists and statisticians. Data team members have the ability to add and backout files from the database. The epidemiologists and statisticians access the database to download files for their research purposes.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 8, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP Division of TB Elimination Image Library - (DTBE Image Library) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: N/A

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DTBE Image Library

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Sara Thrift

10. Provide an overview of the system: A central storage and retrieval system for current and historical TB –related digital images for DTBE.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No IIF or any other information

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No IIF or any other information

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No IIF or any other information

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No IIF or any other information

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 15, 2008

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP Grants Central Station System for Analysis of Intramural and Extramural Funds - (SAIEF) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 20, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: (FY08) 009-20-01-01-02-1000-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: GCS (Grants Central Station) Saief360

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Nancy Haban

10. Provide an overview of the system: Saief360 is used throughout the Agency by CIO’s and Divisions to effectively manage its financial resources. The system is used to provide a common system for tracking extramural funds. Saief360’s Extramural module tracks the funding of projects using the most commonly mechanisms i.e. contracts, announcements, memorandums of agreement etc.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Saief360 will contain information pertaining to

- CAN Code

- Doc no

- Admin code

- Announcement Name

- Announcement Number

- Grantee Name (organization name)

- Grant Year

- Budget Year

- Award number

- Contract no

- Contract Master title

- Contractor Name (company name)

- Option Date

- Contract Year

- contract mod number

- MIM No [Memoranda of Understanding (MOU), Interagency Agreements (IAG), and Memoranda of Agreement (MOA)]

- MIM title

- Program

- Transaction type

- CAN

- Cost Center

- Allowance

- Project code

- Budget activity

- Description

This application does not contain IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: This application does not contain IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: This application does not contain IIF.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP Group Event Management System - (GEMS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: PIA Validation

1. Date of this Submission: May 20, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-02-00-02-9509-00

N/A

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Group Event Management System (GEMS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Rashad Burgess

10. Provide an overview of the system: The GEMS mission is to enable the Capacity Building Branch (CBB) to reduce the manual administration of training efforts that are aimed towards increasing the capacity of health departments and community based organizations to deliver HIV prevention intervention. The GEMS web-based application will be launched from the Capacity Building Assistance Portal (CBAP) bringing together CDC employees, Capacity Building Assistance (CBA) providers, directly funded Community Based Organizations (CBO) and Health Departments to a single online gateway to access CBA resources. CBAP is located at the following web site: http://wwwdev.cdc.gov/hiv/cba/default.htm. GEMS currently consists of two functional areas: a training calendar enabling registrants to register for events and coordinators to post and un-post events, and a profile management center enabling registrants to submit business contact information to create and modify their own profiles.

GEMS Training Calendar events are posted to GEMS by the Calendar Coordinator. Training is offered by the CBB Training and Development (T&D) team. This team provides logistics, instructors, and technical assistance. GEMS registrants can complete event registration requests, which are received by the system and placed on the course roster or waitlist according to programmed business rules. The system sends an email confirmation of enrollment to the registrant. The system will also provide analytical and transactional reporting.

A highlight of GEMS essential system functions are as follows:

• Maintain training calendar

• Register for events

• Issue completion certificates

• Submit events

• Generate reports

• Administer the system

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Name and contact information of organization employees will be shared with Capacity Building Assistance Providers who will be conducting the class for which the person is registered.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: System collects the business address of the organization the person is employed by and uses it to send course completion certificates after course completion. The system does not collect any personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: There is no personal information collected therefore no special security is needed. Data is stored in a SQL database which is accessible only via the application. Only those with admin rights in GEMS can access the information.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP Hepatitis Experimental Primate System (HEPS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9122-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Hepatitis Experimental Primate System (HEPS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kris Krawczynski, MD, PhD

10. Provide an overview of the system: HEPS is a CDC Intranet web application in Experimental Pathology Laboratory (EPL), Division of Virual Hepatitis (DVH), NCHHSTP, CDC. It helps EPL technologists and supervisors to collect, manage, analyze and report animal (mainly primate) hepatitis experimental data. The information includes when and from where the animal is received at CDC, its date of retirement, basic health information, physical and physiological measurements, clinical serologies, liver function assays, In-House PCR results and sample storage info. Study protocols are documented in the online system. All the information stored in the database can be retrieved in a number of ways. The HEPS system also interfaces with the DMS to allow orders for serological testing on an animal's serum, and the retrieval of test results

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No (No sensitive info collected)

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No (No sensitive info collected)

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 5, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP HIV/AIDS Reporting - (HARS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9122-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: HIV/AIDS Reporting System (HARS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Sam Costa

10. Provide an overview of the system: HARS is a multipurpose surveillance system designed to monitor the total number of reported HIV/AIDS cases from public, private, and government reporting facilities. This surveillance system monitors the total number of AIDS cases reported in the 50 States, DC, six separately funded cities, US territories and possessions, and HIV cases in States that require reporting of persons with HIV (not AIDS) . The database is cumulative, containing all case reports since 1981

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Public health data only. Case reports are received from providers who voluntarily report to the local surveillance program by phone with a surveillance representative completing the case report form and from surveillance representatives who abstract medical records in hospitals and private physicians’ offices to complete the case report form. Data is either manually entered or imported into HARS at the state or local level. Data is transferred to CDC monthly through the filtering of new and updated records. The transfer process removes identifying information (IIF) from the transfers, encrypts the file using SEAL and submits to CDC through the use of the Secure Data Network (SDN) file upload procedure. CDC produces national datasets quarterly, which are used to produce the annual national HIV/AIDS surveillance report, as well as numerous other epidemiological analyses.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: DOB only IIF within datasets. Access to the network is controlled with standard CDC IT security policies. Additionally, datasets are secured on a secure data store with limited user rights.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 27, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP Sisters Empowered Sisters Aware - (SESA) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-01-02-1000-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Sisters Empowered, Sisters Aware (SESA)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Lisa Kimbrough

10. Provide an overview of the system: Sisters Empowered, Sisters Aware (SESA) is a project designed to increase the number of African American women who know their HIV status (it is an HIV testing project). The project involves the evaluation of four HIV testing strategies designed to locate women with undiagnosed infection.

The SESA data collection system is a client/server application developed in C#.NET with Microsoft SQL server 2005 as backend. The system contains client-level demographic, testing strategy, and counseling/ testing/referral (CTR) data. The system will also collect data pertaining to cost-effectiveness analysis and allow site managers to run queries and reports that summarize data associated with a specific time period.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: HIV CTR, demographic, testing strategy, and cost-effectiveness data; does not contain any IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 8, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCHHSTP STuberculosis Trials Consortium Client Server - (TBTC CS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9122-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Tuberculosis Trials Consortium Client Server (TBTC CS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Lorna Bozeman

10. Provide an overview of the system: The function of the application is to store study data for the clinical trials done by the TB Trials Consortium. The TB Trial consortium is a group of hospitals/research institutions/academic institutions funded by CDC to carry out trials for treating TB patients with new drugs. The applications also provide other modules which facilitate drug distribution, manage drug inventory levels and/or reorder drugs for the trial sites in a timely fashion. Some other reports like labels, patient visit schedules, patient enrollment count at different sites and reports for missing data are also generated

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 8, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCIRD Active Bacterial Core Surveillance (ABC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9721-00

4. Privacy Act System of Records (SOR) Number: System does not constitute a “system of records” under the Privacy Act. Data is not retrieved by name, SSN or other unique identifier.

5. OMB Information Collection Approval Number: 0920-0009

6. Other Identifying Number(s): No

7. System Name: Active Bacterial Core surveillance (ABCs)

Active Bacterial Core surveillance (ABCs)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Carolyn Wright

10. Provide an overview of the system: ABCs is an active, population- and laboratory-based surveillance system conducted in ten Emerging Infections Program sites (EIPs): California, Colorado, Connecticut, Georgia, Maryland, Minnesota, New Mexico, New York, Oregon, and Tennessee. Surveillance is conducted for invasive bacterial diseases due to pathogens of public health importance. For each case of invasive disease in the study population, a case report with basic demographic information is completed and, in most cases, bacterial isolates from a normally sterile site from patients are sent for further laboratory characterization. ABCs data are used to determine the incidence and epidemiologic characteristics of invasive disease due to the pathogens under surveillance and to provide an infrastructure for further research, such as special studies aimed at identifying risk factors for disease, post-licensure evaluation of vaccine efficacy, and monitoring effectiveness of prevention policies.

Data originates at the state level and aggregate, de-identified data is sent to CDC. Data are not retrieved by any unique identifier.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Aggregate data are shared in electronic form with other divisions within CDC for the purpose of generating reports and manuscripts.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: For each case of invasive disease in the surveillance population, a standard case report form with basic demographic and clinical information is completed. These data are used to determine the incidence and epidemiologic characteristics of invasive disease due to Haemophilus influenzae, Neisseria meningitidis, group A streptococcus, group B streptococcus, Streptococcus pneumoniae, and methicillin-resistant Staphylococcus aureus in several large populations; to determine molecular epidemiologic patterns and microbiologic characteristics of public health relevance for isolates causing invasive infections from select pathogens; to provide an infrastructure for further research, such as special studies aimed at identifying risk factors for disease, post-licensure evaluation of vaccine efficacy, and monitoring effectiveness of prevention policies.

IIF collected is date of birth, race, ethnic origin, sex, age, weight, height, and whether individual is nursing home resident. System does not contain, name, SSN or other unique identifier.

States voluntarily submit aggregate, de-identified data to CDC.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: Notification and consent takes place at the state level. CDC receives only de-identified, aggregate data.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Administrative controls: ABCs data are stored in aggregate form on the agency’s mainframe. Access to aggregate datasets is restricted to approved CDC users. Approved users are granted read only access through the agency’s mainframe system by the database administrator. Host system security and physical controls for IT infrastructure and services are established in the Service Level Agreement between the Information Technology Services Office (ITSO) and CDC.

Technical controls: user ID, passwords, firewall, intrusion detection system, common access card and smart cards.

Physical controls: guards, ID badges, key cards, and close circuit TV.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 1, 2008

Date Published: Sept 8, 2008ps

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCIRD Conference Room Scheduling System - (CRSS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: Initial PIA Migration to ProSight

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-02-00-02-9309-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Conference Room Scheduling System

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Karron Singleton

10. Provide an overview of the system: The Conference Room Scheduling System is required by ITSO to schedule conference rooms and the services that are available in Conference Rooms. It is in use across the CDC enterprise.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Userid associated with a conference room reservation

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Conference room scheduling information and voluntary userid for contact event coordinators

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 10, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCIRD GID Travel and Consulting Web Application - (GID Travel) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-02-00-02-9309-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: GID TRAVEL

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Robert Avey

10. Provide an overview of the system: The GID Trav system collects data on prospective travel candidates for NCIRD/GID’s international travel programs including the STOP program. The site also allows GID staff to enter their travel itineraries to support the reporting requirements of CDC’s international partners

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): IIF is shared and accessible within GID for purposes of evaluating candidates for international travel.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information collected includes name, phone, address, limited employment history, email address. Submission of all data is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No change policies exist.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Secured in SQL Server database accessible only to those with administrative access to view the data. CDC staff that enter their personal profile data may access their own data through the website.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCIRD Grants Application Tracking Information System - (eGRATIS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-04-00-02-1036-00

4. Privacy Act System of Records (SOR) Number: System in development

5. OMB Information Collection Approval Number: System in development

6. Other Identifying Number(s): N/A

7. System Name: eGrATIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Victor Negron

10. Provide an overview of the system: Track immunization grants awarded to State and Local Health Departments from application through award and budget changes.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: eGrATIS’s will collect programmatic information from CDC grantees (state, cities and territories) through a common internet interface. eGrATIS operationalizes the entire life cycle of the grants application process from inception to completion. The system generates reports, supports queries, standardizes reporting practices, and consolidates program information. What IIF collected through eGrATIS is mandatory

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: eGrATIS is to be hosted on the Secure Data Network (SDN). The front-end of the application authenticates all users using X.509 digital certificates which are provided to the front-end server upon attempted login. Transport Layer Security (TLS) protects data in transit while users access data within the application.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W.Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCPDCID AIDS Inventory (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jun 19, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9324-00

4. Privacy Act System of Records (SOR) Number: 09-20-0169

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: AIDS Inventory

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Dollene Hemmerlein

10. Provide an overview of the system: System inventories 30+ years of CDC specimens collected during investigations, outbreaks, congressionally mandated studies and CDC funded studies.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Testing labs and study investigators for results matching and use

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Data collected is decided upon by investigator as relevant to study; mostly voluntary

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: All studies receive IRB approval and contain consent forms for collection and use of data and specimens

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All IIF is blocked from view except by authorized users and released only after permission of investigator

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P Madden

Sign-off Date: Jun 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCPDCID Early Aberration Reporting System - (EARS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9721-00-110-246

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Early Aberration Reporting System (EARS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Lori Hutwagner

10. Provide an overview of the system: The Early Aberration Reporting System (EARS) was pioneered as a method for monitoring bioterrorism during large-scale events. Various city, county, and state public health officials in the United States and abroad currently use EARS on syndromic data from emergency departments, 911 calls, physician office data, school and business absenteeism, and over-the-counter drug sales. The EARS program presents its analysis in a complete HTML Website containing tables and graphs linked through a home page. Viewing EARS output requires only a Web browser.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: EARS will voluntarily collect daily counts of syndromic information. This information will be used to monitor for possible aberrations or spread of disease such as ILI.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 12, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCPDCID Global Migration Database - (Global Migration) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9721-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Global Migration Database (Global Migration)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Rob Murphy

10. Provide an overview of the system: The Global Migration project is an effort to gather air traffic data for modeling and analysis purposes. A data feed has been established with the Federal Aviation Administration’s (FAA) Enhanced Traffic Management System (ETMS). DGMQ receives a daily summary of flight information pulled from the archive process supported by the ETMS system. This feed is public data and available to and used by a number of commercial air traffic websites. The unique and powerful aspect of this project for CDC is the collection of the daily data feed into one large database (dataset) for statistical and situational analysis. At this point there is no user interface, the database servers as an air traffic warehouse to be accessed by statisticians, data analysts and queried for situation driven information.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The Global Migration project is an effort to gather air traffic data, from the Federal Aviation Administration (FAA), for modeling and analysis purposes. DGMQ receives a daily summary of flight information pulled from the archive process supported by the ETMS system. This feed is public data and available to and used by a number of commercial air traffic websites.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name:

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 8, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCZVED Arbovirus Diseases Branch Inventory (ADBI) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-1481-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Arbovirus Diseases Branch Inventory (ADBI)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Roger Nasci

10. Provide an overview of the system: This is an Access Program, totally. The front end is Access and the back end is Access. The system resides on a file server in Fort Collins (fcid-vbi-1). The system stores scientific data and tracks virus seeds, antibodies, and antigens of the ADB Virus collection along with their storage location. The system increments and decrements the supply of antigen as it is used by Branch Researchers in order to flag supply for restock.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: N/A

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 9, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCZVED Division of Parasitic Diseases - (DPDx) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jun 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9523-00-110-246

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Division of Parasitic Diseases (DPDx) Website

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Dr. Alexandre J. DaSilva

10. Provide an overview of the system: The purpose of DPDx website is to strengthen the level of laboratorians' expertise to diagnose foodborne and other parasitic diseases. The DPDx website allows users to obtain diagnostic assistance through telediagnosis. Laboratories can transmit images to CDC and obtain answers for their inquiries in minutes to hours. This allows laboratorians to more efficiently address difficult diagnositic cases in normal or outbreak situations and to disseminate information more rapidly. In addition, this method substantially increases the interaction between CDC and public health laboratories (PHLs) as well as among the participating PHLs. To date, 42 laboratories in 39 states and 1 territory have the capacity for telediagnosis, or are in the process of acquiring the hardware to perform telediagnosis. DPDx also provides training for laboratorians.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: NThe DPDx website allows users to obtain diagnostic assistance through telediagnosis. Laboratories can transmit images to CDC and obtain answers for their inquiries in minutes to hours. This allows laboratorians to more efficiently address difficult diagnositic cases in normal or outbreak situations and to disseminate information more rapidly.There is no IIF collected and it is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 18, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCZVED DVBID Reservation System 2 - (RESSYS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 6, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-1479-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC CCID NCZ DVBID Reservation System 2 (RESSYS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Richard J. Peterson

10. Provide an overview of the system: The Reservation System 2 allows only Fort Collins users to reserve division assets (vehicles, laptops, peripherals) for checkout and use. System keeps historical records to track damage and/or loss.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: N/A

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 5, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCZVED Early Detection Research Network-Cervical Cancer Clinical Epidemiology and Validation Center (EDRN-CCCEVC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9721-00-110-246

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Early Detection Research Network-Cervical Cancer Clinical Epidemiology and Validation Center (EDRN-CCCEVC)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Elizabeth R. Unger PhD, MD

10. Provide an overview of the system: The system is an integrated database designed to create, maintain and use a biorepository of samples to discover and validate biomarkers to improve cervical cancer screening. The system includes data on clinical, epidemiologic and laboratory values that are linked to the inventory of biologic samples. No personal identifiers of any kind are included.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No IIF information is collected. System is completely anonymous and links biologic samples with patient demographics and disease status. Data will be shared with ERNE investigators seeking to develop or validate biomarkers for cervical cancer screening. It is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 28, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCID NCZVED National West Nile Surveillance System - (ArboNet) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 24, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-1480-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: National West Nile Surveillance System (ArboNet)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Marc Fischer

10. Provide an overview of the system: National West Nile Surveillance System (Arbonet). Allows reporting of arboviral cases from the states. Can be reported through XML or through ArboNet front end.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: N/A

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 11, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CoCHIS NCPHI Division of Knowledge Management Services Decision Support Framework (DKMS-DSF) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-1414-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DKMS-DSF

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Nedra Garrett

10. Provide an overview of the system: DKMS is developing a Decision Support Framework (DSF) of services to capture, aggregate and integrate highly relevant information into public health applications to support decision-making in various areas, such as biosurveillance. This framework will consist of a number of tools, processes and systems to support searching and filtering content using natural language processing techniques, weighting algorithms, probabilistic matching and others methods to gain the highest level of relevancy for the content areas

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Collect: User preference data – Users of the system will be able to provide feedback on the information that they are receiving in order to improve the data received in the future.

Collect: Web/Document content – The Thunderstone appliance indexes content and documents from specifically chosen sources.

Disseminate: Search results – Search results returned by the web service will contain the text of the link, and potentially summary text of the content or document.

Disseminate: Ontological information – A second web service will provide search term expansion by using ontological data stored in the database.

None of the above information contains IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 11, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER Center for Public Health Preparedness Program Activity Database - (CPHP) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

*Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: 09-20-0102

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): None

7. System Name: Center of Public Health Preparedeness Program Activity Database (CPHP)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Joseph Dell

10. Provide an overview of the system: The CPHP Activity Database is an intranet-based tool that allows CPHP Project Officers to electronically view and update required activity information collected from their CPHP centers as part of continuation applications and progress reports¿. The CPHP Activity Database includes program information for the respective budget periods. Activities are designated within the database as either Program Activities (education and training, partner-requested, or supportive) or Network Activities.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The IIF contained in the system is made available to all program officers within the CPHP program. The application can also be accessed by anyone with access to the CDC intranet.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system displays names, phone numbers, email addresses, and/or mailing addresses for points of contact within schools that participate in the CPHP program. The information is first entered by the schools in a Word document, which is then emailed to the project officer. COTPER IT personal (the developers of the CPHP application) import the data to the SQL database which serves as the backend for all the CPHP applications data. It is visible to anyone with access to the CDC intranet via a web application (the CPHP application). The information can also be updated by anyone with access to the CDC intranet. The application users are aware that this information can be modified and accept the risk as this contact information store is used for convenience. Submission of this information is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The CPHP program officers that collect the original Word forms are responsible for notifying school contacts when changes occur. By submitting the Word document via email, participants accept any risks associated with the unsecured communication method (email) used. They also personally provide the IIF collected.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Standard procedures to secure SQL databases within the shared hosting environment will be used to secure information.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER COTPER Calendar (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Nov 16, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: NO

5. OMB Information Collection Approval Number: NO

6. Other Identifying Number(s): NO

7. System Name: COTPER Calendar

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Joseph Dell

10. Provide an overview of the system: The COTPER Calendar is an ASP application running on a SQL server database, developed to help identify and share key programmatic events and activities from across divisions and the agency. The COTPER Calendar allows anyone behind the CDC firewall to enter an event, but only events approved by the COTPER Calendar content approvers will appear.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No IIF or PII is collected

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No information is collected, only disseminated. No PII is involved.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NO

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER Vacancy Action Tracking System - (CVATS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Nov 21, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: COTPER Vacancy Action Tracking System - (CVATS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Joseph Dell

10. Provide an overview of the system: COTPER Vacancy Action Tracking System (CVATS) is an ASP application running on a SQL server database, developed to track personnel vacancies in all COTPER Divisions, with drop-down action statuses to delineate the status of the current vacancy. CVATS was requested to track vacancies accurately and in one location and their current status within COTPER, eliminating difficult to maintain spreadsheets. Additionally, CVATS maintains a history of prior actions on each specific vacancy, along with tracking the days the action was in each status.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No IIF or PII is collected

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No information is collected, only disseminated. No PII is involved.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Mar 28, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER Sensaphone (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jun 19, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Sensaphone

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Gary Nakashian

10. Provide an overview of the system: The Sensaphone is used by the Division of Strategic National Stockpile (DSNS) to measure and monitor the temperature specified by the manufacture of stored product as a safe storage temperature. The purpose behind this system is to allow the assets to be in the federal Shelf Life Extension Program (SLEP), increasing the effective shelf life of the materiel. This monitoring system ensures the SNS Program staff is able to ensure that conditions of materiel comply with SLEP guidelines.

The system architecture contains a program called S2050 that polls data off of Sensaphone units by dialing into them using analog modems, and then downloads the data into a Borland Interbase database managed by SNS system administrators. The data can only be viewed by authorized personnel.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NO

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The Sensaphone is used by the Division of Strategic National Stockpile (DSNS) to measure and monitor the temperature specified by the manufacture of stored product as a safe storage temperature. No IIF is contained in the Sensaphone application.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: NO

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NO

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Fellowship Management System (FMS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: PIA Validation

1. Date of this Submission: Aug 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: Component of CDC PH Communications for Workforce & Career Development (system UID # 1310)

4. Privacy Act System of Records (SOR) Number: SORN 09-20-0112: Fellowship Program and Guest Researcher Records

5. OMB Information Collection Approval Number: 0920-0765

6. Other Identifying Number(s): NO

7. System Name: Fellowship Management System (FMS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Elinor Greene

10. Provide an overview of the system: The Fellowship Management System will allow applicants to apply to CDC fellowships on-line and will track fellowship alumni in one integrated database. The target audience consists of professionals in public health, epidemiology, medicine, economics, information science, veterinary medicine, nursing, pharmacy, public policy and related professions, and medical, veterinary, and graduate students. Applicants choosing to apply to one or more CDC fellowship(s) will enter their information once and alumni who choose to participate in the alumni directory will have the option of providing updates to information that has changed. Information about alumni who provide consent will be included in standard downloadable reports including the alumni directory. Alumni will use the directory to facilitate networking, per their request. CDC will use the information collected for processing application data, selection of qualified candidates, maintaining a current alumni database, documenting the impact of the fellowships, and generating reports.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): -- Present or Past applicants (they can only access their own information for verification/correction of their own data).

-- CDC/OD/OWCD Fellowship Administrators (for processing application data, selection of qualified candidates, maintaining a current alumni database, documenting the impact of the fellowships, and generating reports).

-- Fellowship alumni (can only access electronically their own information for data verification and/or correction of their own records).

-- Fellowship alumni will have access to standard downloadable reports including the alumni directory. The purpose of sharing this information is to facilitate networking among the alumni (per their request). Alumni must provide consent to allow their information to be included in the directory. Only the names and fellowship year, information already in the public domain, will be included for alumni who opt out of sharing their information.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: IIF includes: Name, Email Address, Mailing Address, Phone Numbers, Fellowship Entry Year, Citizenship Information, Education and Training, Work Experience, Volunteer Activities, Research Grants, Presentations, Publications, Interests, Skills and Abilities. CDC will use the information collected for processing application data, selection of qualified candidates, maintaining a current alumni database, documenting the impact of the fellowships, and generating standard downloadable reports including the alumni directory and a listing of current fellows. All submissions of data are voluntary including participation in the alumni directory.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: Should major changes ever occur to the system, CDC/OD/OWCD Administrators will notify individuals whose IF is in the system by email asking them to log on to the system to provide electronic consent as appropriate. The EIS Bulletin will also include an announcement of notification and request alumni to log on to the system to provide electronic consent as appropriate.

Individuals will be notified as to what IIF is being collected from them and how the information will be used or shared when they first log into the system as an applicant or an alumnus and every time they log onto the system thereafter. Alumni will provide electronic consent before they can enter their own data and they will always have the option of retracting their consent.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Admin.: Access only by applicants to their own records, access only by alumni to their own records, or by CDC/OD/OWCD Administrators to all records.

Technical: Located in DMZ, encryption of passwords.

Physical: Mid-tier Data Center under ITSO controls.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 15, 2008

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Goals Tracking System - (GTS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9224-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Goals Tracking System (GTS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Apoorva Patel

10. Provide an overview of the system: System provides Global Immunization Division with the ability to track activities by location, staff member, team and date. Each activity can be connected to a division product, objective and strategic goal and reports can be created showing goals to activities.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Information is shared with other users to allow users to assign staff members to division activities.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: System provides Global Immunization Division with the ability to track activities by location, staff member, team and date. Each activity can be connected to a division product, objective and strategic goal and reports can be created showing goals to activities.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: Electronic consent will be sent out to all individuals with IIFs in the system.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Access only via internal network.

Users file has 256-bit encryption.

Building is secured to CDC staff members only.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 9, 2008

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCCDPHP Pregnancy Nutrition Surveillance System - (PNSS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

*Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 09-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: 09-37-0024

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: Pregnancy Nutrition Surveillance System (PNSS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Karen Dalenius

10. Provide an overview of the system: The PNSS collects clinic data for pregnant and postpartum women, and their newborn infants, from state, territorial and Indian Tribal Organizations WIC and MCH programs around the country; logs incoming files and performs extensive editing on the file records; produces data quality reports detailing the results of the edits and transmits those reports back to the contributors; merges the edited data into master files in a SQL Server data warehouse; and produces and publishes statistical reports, graphics/maps based on aggregated data from the data warehouse. Locate a system overview on our website at http://www.cdc.gov/pednss.

We use the term “contributor” to refer to the state and territorial health departments and Indian Tribal Organizations (ITO's) that submit data to the PNSS.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system shares IIF only with an original PNSS contributor when that contributor requests copies of their cleaned and edited files. If non-contributors request PNSS records, the following fields are stripped from national files: State and sub-state (or randomly assigned 3 character codes are assigned), Clinic Code,

Initial Visit Date,

Woman's Date of Birth,

Woman's Alphanumeric ID (Mother's numeric ID and Mother's Alpha-ID on pre-2004 CDC PNSS master files), and Infant Alphanumeric ID (Infant's Numeric ID and Infant's Alpha-ID on pre-2004 CDC PNSS master files). Date interval fields on the PNSS master file are also assigned a random number added to or subtracted from them. A different random number is generated for each record.

If a non-contributor needs one or more of these fields on a national PNSS file or they want individual contributors files, they must obtain written permission from the contributor(s) whose records they are requesting. Identifiers are almost always stripped at the request of contributors. Under FOIA requests, we cannot make sharing of data contingent upon obtaining permission from the contributor. However, FOIA does protect personal privacy interests. Data that are identifiable to a specific individual are protected from disclosure. In the event of a FOIA request for data, we strip the following identifying information from the records prior to distribution to a requesting non-contributor: Clinic Code and Identifier.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The following critical and core fields are currently populated on most PNSS records and/or have been populated on PNSS records in the past: State Code, Substate Code, Clinic Code, County Code, Source of Data, Completion Code, Initial Date of Visit, Postpartum (PP) Date of Visit, Woman’s Alphanumeric Identifier, Woman’s Date of Birth, Race/Ethnicity, Household Size, Household Income, Date of Last Menstrual Period, Expected Date of Delivery, Height of Woman, Prepregnancy Weight, Weight of Woman-Prenatal Visit, Weight of Woman-PP Visit, Positive or Negative Weight Gain, Total Weight Gain, Hemoglobin-Prenatal Visit, Hemoglobin-PP Visit, Hematocrit-Prenatal Visit, Hematocrit-PP Visit, Parity, Date Last Pregnancy Ended, Medical Care Began, Date Enrolled in WIC, Cigarettes/Day-3 Months Prior to Pregnancy, Cigarettes/Day-Prenatal Visit, Cigarettes/Day-Last 3 Months of Pregnancy, Cigarettes/Day-PP Visit, Drinks/Week-3 Months Prior to Pregnancy, Drinks/Week-Last 3 Months of Pregnancy, Infant Identifier-Alphanumeric, Infant’s Date of Birth, Number of Infants, Born Alive or Dead, and Infant’s Birthweight. The following supplemental fields are currently populated on some PNSS records and/or have been populated on PNSS records in the past: Zip Code, Migrant Status, WIC/Food Stamp/Medicaid/TANF Participation, Date of Hemoglobin/Hematocrit Measure-Prenatal Visit, Date of Hemoglobin/Hematocrit Measure-PP Visit, Gestational Diabetes-PP Visit, Hypertension During Pregnancy-PP Visit, Multivitamin Consumption Prior to Pregnancy, Multivitamin Consumption During Pregnancy, Household Smoking-Prenatal Visit, Household Smoking-PP Visit, Currently Breastfed, Ever Breastfed, Infant Sequence Number, Alive or Dead-PP Visit, Infant Sex, Formula Use, Marital Status, Smoking Changes During Pregnancy-Prenatal Visit, Smoking Changes During Pregnancy-PP Visit, Previous Pregnancies, Drinks/Day and Drink Days/Week-Prenatal Visit, and Drinks/Day and Drink Days/Week-PP Visit. CDC uses this information to monitor trends in the prevalence of prenatal risk factors which are major predictors of low birthweight, and to provide summary data to contributors to assess coverage, targeting, and effectiveness of maternal health programs. DNPAO epidemiologists and statisticians a) create and manage cohorts of women for PNSS longitudinal analyses and b) link PNSS records to Pediatric Nutrition Surveillance (PedNSS) records in reference to identifiers.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: PNSS records are submitted by state, territorial, and Indian Tribal Organization WIC programs and state maternal health programs, all of which require informed consents to be signed by participants upon program enrollment.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Access to the PNSS database is governed through an assigned GP-DN-ro group managed by the NCCDPHP SQL database administrator, Terrine Mathews, with input from our team. This group is limited to Data Systems and Surveillance Team members and about eight DNPAO epidemiologists and statisticians. Data team members have the ability to add and backout files from the database. The epidemiologists and statisticians access the database to download files for their research purposes.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 11, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCIRD Registry Sentinel Project (Sentinel) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 01-04-02-9322-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: NCIRD Registry Sentinel Project (Sentinel)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Dianna Bartlett

10. Provide an overview of the system: To understand changing patterns of acceptance of immunization soon enough to properly respond, the public health community requires an instrument that can monitor the public’s response to events in a timely manner. NCIRD Sentinel Sites report aggregate immunization coverage data to NCIRD on a quarterly basis through a web-based data entry system. The data are stored in a SQL Server database from which standardized charts are generated for review by the CDC Data Manager.

The system contains business contact information (name, phone and fax numbers and email address) of the state health department employee who does the data entry.

All other data provided by the sentinel sites do not contain IIF.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Sentinel Sites will provide NCIRD with aggregate vaccination coverage information and data quality measurements both quarterly and on an ad-hoc basis. Sentinel Sites evaluate quarterly the current coverage of 4:3:1, 4:3:1:3, 4:3:1:3:3, 4:3:1:3:3:1 in the 19-35 month old population of their sentinel group and compare those numbers with estimates from the most current National

Immunization Survey. Sentinel Sites also report quarterly on the number of doses of DTaP, polio, varicella, Hib, Hepatitis B, Hepatitis A, PCV7, and MMR administered to various age groups within the sentinel group.

IIF collected is business contact information (name, phone and fax numbers and email address) of the reporter who is doing the data entry. All other data provided by the sentinel sites do not contain IIF.

Participation by sentinel sites is voluntary.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: Only IIF collected is business contact information (name, phone and fax numbers and email address) of the reporter who does the data entry for business purposes.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Administrative controls: IIF data are backed up daily and copies stored in a separate facility. Technical controls: Access to the data is controlled by user ID and password in addition to the user ID and password needed to access the network. Physical controls include security guards, ID badges, cardkeys and cipher locks.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 1, 2008

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCPHI NCHS National Death Index - (NDI) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: N/A

4. Privacy Act System of Records (SOR) Number: 09-20-0166

5. OMB Information Collection Approval Number: 0920-0215

6. Other Identifying Number(s): N/A

7. System Name: NATIONAL DEATH INDEX

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: ROBERT BILGRAD

10. Provide an overview of the system: The National Death Index (NDI) is a file of identifying death record information for all U.S. deaths occurring since 1979. This computer-matching service assists health researchers in determining whether specific study subjects have died, and if so, provides researchers with the states and dates of death and death certificate numbers. The NDI Plus service also provides the cause of death codes derived from the decedents' death certificates. Since 1982 the NDI has performed over 4,000 searches involving over 50 million records submitted by researchers involved in a wide variety of activities -- including clinical trials, post-marketing drug surveillance, occupational health studies, cancer and other disease registries, and longitudinal studies involving large population groups.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system confirms the fact of death for health researchers’ study subjects and releases the date of death, state of death and death certificate number.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The NDI uses identifiable death record information to assist health researchers to determine if their study subjects died and to obtain the decedents’ causes of death. The IIF is obtained voluntarily from state vital statistics offices via contracts

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The data are administrative information collected by the state health departments in conformity to state laws. When a major change occurs to the system we are required to notify the states.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Data is secured on the CDC mainframe with access restricted to only those NCHS programmers involved in maintaining and using the system. Data released to approved health researchers are encrypted on a CD, are password protected, and are sent to researchers only via Fedex.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 8, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO CPIC Enterprise Systems Catalog - (ESC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

*Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jun 19, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-02-00-02-0877-00

4. Privacy Act System of Records (SOR) Number: 09-90-0024

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Enterprise Systems Catalog (ESC)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Sandra McGill

10. Provide an overview of the system: The system is used by CDC’s CPIC office to address the responsibilities assigned to the CDC under HHS and Federal Guidelines for IT Capital Planning and Investment Control. All active CDC IT investments that store, analyze, process, manage, distribute, and/or provide access to electronic information are entered into ESC and this information is used by the CDC to accurately report and categorize IT spending.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): ESC is available for stewards and system owners to see the Capital Planning Investment information and security information for their system. It lists the first and last name of the individual stewards (security, technical, business) if there are any questions/issues surround that system.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The agency maintains the first and last name of CDC employees that have responsibilities for information in ESC or have important responsibilities associated with the systems cataloged by ESC.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: When a system is entered into the ESC, it asks the employee to list the names of the stewards of the system. If there are changes to these names, the administrator can go into the system and make those corrections. The stewards are identified, notified and aware that they are listed as a steward in the ESC for the system they are stewards for.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Administrative Controls: New users must have approval of the business stewards to view capital planning data. All CDC users have ready-only access to system overview screens that displays other usernames that are assigned to business, data, security or data steward roles. User access privileges are revoked when a user leaves the CDC or a user no longer requires access to the system.

Technical Controls: User access to IIF is role based.

Physical Controls: IIS and SQL servers secured in ITSO facility at the CDC Roybal Campus in Atlanta.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jun 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO ITSO Multi User Share Tool - (MUST) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 24, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: No

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Multi-User Share Tool(MUST)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Wayne Knight

10. Provide an overview of the system: MUST provide the ability of Active Directory Member Group Data Stewards to manage user access to specified file shares in the CDC domain.

The system will provide a quicker turn around time for the CDC User (customer) and eliminate having to impact multiple technicians throughout the infrastructure to make modifications to AD groups.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Data collected, disseminated, and/or collected pertains to CDC accountable assets(property), network information, ADP information, and CDC user information without any distinguishing identifiable information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No IIF is collected, disseminated, or maintained in the system.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No Information in Identifiable Form is collected or transmitted.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 10, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO Managing Accounting Credit Card System (MACCS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-1262-00-405-143

4. Privacy Act System of Records (SOR) Number: 09-90-0024

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Managing Accounting Credit Card System (MACCS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Teresa Kinley

10. Provide an overview of the system: MACCS was developed by Starry Associates, Inc., as a Commercial Off-the-Shelf (COTS) software package in response to Federal Government needs in the area of Purchase (Credit) Card management.

It helps to support the GSA SmartPay VISA Purchase Card program that is administered at CDC by the Procurement & Grants Office (PGO).

MACCS is a web-based software solution that automates the logging, tracking, and obligation of credit card transactions. Each business day, MACCS receives credit card transaction records from US Bank via secure FTP. And each business day, MACCS sends obligation records to UFMS for those transactions that are matched and registered against purchases logged into MACCS by users (cardholders and approvers). Once a month, MACCS receives an invoice file from US Bank and reconciles this monthly summary with the daily transactions from the previous month. This function is used by FMO Accounts Payable in determining if the invoice from US Bank is accurate. The MACCS project at CDC is a shared venture between FMO, PGO, and MISO.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): MACCS discloses the names of CDC VISA credit card holders and their CDC VISA credit card numbers. In addition, MACCS discloses the names of merchants for CDC VISA transactions, and in the case of VISA check transactions, the merchants’ addresses and their taxpayer identification numbers. This is available to only authorized personnel within CDC for the purpose of financial management of federal credit card purchases. Card numbers are masked (except for the last 5 digits) to all users except administrators.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Card user name and credit card number; approving official name and approving official account number; VISA merchant name, address, and TIN. The purpose of collecting this information is for the financial management of federal credit card purchases. Submission of this information is mandatory.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No data uses have changed since the notice at the time of the original collection.

Any changes to the system would be driven by the needs of the GSA SmartPay VISA Purchase Card program administered at CDC by PGO. The program administrator at CDC/PGO notifies all program participants and MACCS users of program changes, and their related impact to MACCS.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Only authorized users have access to the system. Password protection to the system is in place. Credit card numbers are masked (except for last 5 digits).

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 9, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MASO Content Management System - (CMS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 19, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1508

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Content Management

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: This system provides a proactive method to remind content providers to perform timely reviews of their content for quality and accuracy.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: N/A

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MASO Federal Advisory Committee Management - (FACM) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 20, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-06-02-9409-00

4. Privacy Act System of Records (SOR) Number: 09-90-0059

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Federal Advisory

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: This system is a record of Federal Advisory committees to use in submitting federal register notices and completing member conflicts of interest.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Federal Advisory Committee Management

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: contact information – mandatory

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Limited full access to database – provided only to the team in MASO

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MASO Mailstop - (MS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 19, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1507

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Mailstop

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: The Mailstop System is an informational sytem that stores the mailstops of all the CDC locations..This is a intranet-based application used to maintain CDC Mailstop Data.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Does not collect information

Information only.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MASO Print Tracking System (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 19, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1514

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Print Tracking

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: The Print Tracking system allow end users to enter requests into the system. It allows customer to check the status of their jobs and get cost information. It allows the print specialist to write a specification to check the status on the job and to record the delivery information and return of materials. It also allows the Printing Office to resport to FMO on fund obligation.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

PRINT TRACKING Does Not Collect or Share IIF

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: End user enter request for printing services

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: PRINT TRACKING Does Not Collect or Share IIF

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MISO Electronic Data Exchange - (EDI) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-09-02-0984-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Electronic Data Interchange

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Michael Lukiart

10. Provide an overview of the system: The function of the EDI system is to convert mainframe flat files to ANSI X-12 edi files and the reverse, (X-12 to flat files).

The system pulls Order files (flat) from the mainframe via FTP, converts the files to X-12 format, and pushes them to the Value Added Network (VAN) via FTP. The system then pulls X-12 Invoice files from the VAN via FTP, converts them to flat (mainframe) files, and pushes them to the mainframe via FTP.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NO

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MISO Labware (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-01-02-1170-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Labware

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Angela Cox

10. Provide an overview of the system: Labware is a laboratory supply catalog application. It is used by laboratory workers to order products from a catalog that have been purchased and inventoried by CCID. Additionally, the labware application will also keep track of the quantities that are ordered; a report can be generated showing dollar amounts being ordered each from division and the application can keep track of orders and total costs of orders and fill the order for the requesting lab.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO MISO Web Services Logger - (WSLogger) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jul 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-09-02-0984-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Web Services Logger (WSLogger)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Sandy Chapman

10. Provide an overview of the system: WSLogger is a component that can be attached to any MISO web service to transparently begin capturing utilization information about that web service. The Component registers usage and benchmark information into the SQL database for management reporting. Information captured is limited to few data elements such as User-ID of caller, date and time, name of the web service, elapsed time, and name of the method.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NO

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system will display utilization numbers that help in management decision making. Number of calls, number of users, number of errors, etc,

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The system only displays data collected from the WSLogger system.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 9, 2008

Date Published:Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO OSEP HHS Identity (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 16, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-00-02-00-02-0030-00

4. Privacy Act System of Records (SOR) Number: HHS 09-90-0020

5. OMB Information Collection Approval Number: 3206-0005, SF-85, SF-86 (?)

6. Other Identifying Number(s): GS-35F-0306J (FISMA ID), I-9 form 1615-0047, Declaration for Federal Employment 3206-0182 (?)

7. System Name: OS ASRT HHS Identity Management System

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Ken Calabrese

10. Provide an overview of the system: This system will produce the new ID badge for all HHS employees and contractors across all HHS Operating Divisions

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): HHS will use the information on the card and may use some of the stored information when person accesses federal facilities, computers, applications, or data to prove person's identity and right of access.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The agency will collect the following information: full name, facial photograph, two fingerprints, date of birth, home address, home phone number, background investigation form, the results of a background check, the approval signature of the person who registered the user in the system, card expiration date, the card serial number, and copies of the documents used to verify identity, such as driver's license or passport.

The investigation is a federal government job requirement. Those who refuse to provide personal information will not meet the requirements of the job and will therefore not be considered further. Current employees who do not meet these requirements will be terminated.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: PIV card applicants are required to complete applicant training about the PIV process and must print out a training completion form. In addition, upon receipt of the badge, applicants are required to sign a statement that s/he knows his/her rights and responsibilities.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: The database and individual OPDIV feeder servers are located within secured buildings. Different degrees of security have been implemented at all location, with some including Biometrics and Closed Circuit TV.

Technical controls which minimize the possibility of unauthorized access, use, or dissemination of the data in the system are also in place. These include: user identification, firewalls, VPN, encryption, Intrusion Detection System and Common Access Cards.

Guards, ID Badges and Key cards further ensure IIF will be secure.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. madden

Sign-off Date: May 16, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD ITSO WAN Video Conferencing System - (ENVISION) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: Initial PIA Migration to ProSight

1. Date of this Submission: Jan 28, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-02-00-01-1152-00-404-139

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: ENVISION

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Joe Jackson

10. Provide an overview of the system: The ENVISION System provides video conferencing capabilities to employees at various points across the CDC Campuses. The core component of this system is the Multipoint Control Unit (MCU) which controls and manages multiple endpoints to participate in a video conference by providing protocol, data rate, and communication path matching/bridging. ENVISION is the Video Teleconferencing (VTC) system. The MCU and the endpoints are the VTC system, much the same as your telephone and a Private Branch Exchange (PBX) make up a phone system.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NO IIF COLLECTED

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: NO IIF COLLECTED

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: NO IIF COLLECTED

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NO IIF COLLECTED

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 25, 2008

Date Published: Sept 8, 2008

 

No

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD MASO Information Quality - (IQ) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Mar 28, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 875

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: INFORMATION QUALITY

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: This system allows the public to send in requests or complaints regarding dissemination of information from the government. It allows. The public to voice their opinion or complain. This system was mandated by congress – called the Son of Shelby – Public Law 106-554, Section 515.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

INFORMATION QUALITY Does Not collect or share IIF

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Informational site only.

INFORMATION QUALITY Does Not collect or share IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

INFORMATION QUALITY Does Not collect or share IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

INFORMATION QUALITY Does Not collect or share IIF.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD MASO Internal Controls Program - (ICP) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Jan 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1506

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Internal Controls Program

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: This system will implement the A-123 program and serve as a repository of documentation of program functions.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Evaluation of CDC’s ICS as required by OMB-A-123

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Mar 28, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD MASO Office Automation Tracking System (OATS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 15, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1394

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: OFFICE AUTOMATION

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: This system tracks workload of office automation tasks. It has reporting functions for management. It will allow the customers or employees enter the task and the task is routed to the designated person. The individual will perform the task and close the ticket..

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

OFFICE AUTOMATION does not collect or store IIF

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Will collect survey data qualifying whether the work performed was good or not. Will then quantify the data received to generate reports.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: In the survey, the end users are asked if they would like to leave feedback and would they like to be contacted.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

OFFICE AUTOMATION does not collect or store IIF

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD OCOO_National Antimicrobial Resistance Monitoring System_Umbrella_NARMS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: PIA Validation

1. Date of this Submission: Jan 19, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-1481-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: National Antimicrobial Resistance Monitoring System (NARMS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Tom Chiller

10. Provide an overview of the system: National Antimicrobial Resistance Monitoring System (NARMS) was developed as an interagency collaboration between the Food and Drug Administration (FDA), United States Department of Agriculture (USDA), and the CDC. The project successfully developed NARMS versions in each of the divisions of government. NARMS is used to test human, animal, and meat isolates for resistance to clinically important veterinary and human antibiotics. The CDC portion of NARMS performs antimicrobial resistance testing on isolates for selected food borne pathogens (Salmonella, Shigella, Campylobacter, Listeria, Non-cholera Vibrio, non-commensal Enterococcus) originating from and speciated by state/local health laboratories.

NARMS analyzes the resistance data for trends and publishes public reports summarizing trends/key concepts in antimicrobial resistance. These findings are used for such purposes as: expanding the worldwide public knowledge of appropriate use of antibiotics; identifying emerging resistance mechanisms in important food borne pathogens; providing supporting data for regulatory approval/denial of use of antimicrobials in agriculture, and for clinical use in humans. Each division of government maintains its own NARMS data and systems and there is no connectivity between divisions.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): IIF data is restricted to users of the NARMS system.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The agency maintains information forwarded to them from State Labs and Physicians to determine antimicrobial resistance. Access to the NARMS system is controlled by active directory within the CDC network only.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Access to the NARMS system is controlled by active directory within the CDC network only.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD OES Issue Tracking (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Nov 8, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-06-02-1425-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Issues Tracking System

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Alioune Thiam

10. Provide an overview of the system: This application helps log and track issues for the Office of the Executive Secretariat (OES). It allows OES employees to record the subject matter of each issue, the Centers and Coordinating Centers to which the issue is routed, and the actions taken to solve the issue. The data is collected and used for an Executive Leadership Board (ELB) report.

OES is responsible for managing high level issues involving the CDC. The issues are initiated when the public, Congress, etc. requests clarification on matters directly or indirectly related to the CDC. When received, a request is logged in the ITS, assigned a subject, routed to different Centers and Coordinating Centers, categorized and sent to the appropriate person who needs to handle it. Actions that document the steps taken to resolve the issue are also entered into ITS. Information from ITS is used to generate reports that are distributed to the ELB (Executive Leadership Board) for discussion during their meetings.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No IIF in system.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No IIF in system. Only information about issues affecting the CDC and not individual’s information will be collected in the system. The system will be used for strategic planning and reports will only be disseminated to the CDC’s executive leadership.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No IIF in system.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No IIF in system.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC SDMB NCHHSTP Sexually Transmitted Disease Network - (STDNet) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 21, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9521-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Sexually Transmitted Disease Net (STDNet)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Melinda Flock

10. Provide an overview of the system: STDNet takes STD surveillance data that is reported through the National Electronic Telecommunications System for Surveillance (NETSS) maintained by NCPHI. STDNet provides menu driven access to the STD surveillance data for analysis and reporting.

The STDNet application provides users an interface where, for example, they can query a disease by demographics, time and geographic location among other things (e.g., total number of syphilis cases by race, sex for Georgia in 2006). It provides users the ability to produce reports and graphs without having to know mainframe SAS.

The STD surveillance data are used for monitoring the epidemic of certain national notifiable sexually transmitted diseases.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Data is used for monitoring the epidemic of certain national notifiable sexually transmitted diseases; does not contain any IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 19, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Training and Continuing Education Online (TCEOnline) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: PIA Validation

1. Date of this Submission: Aug 27, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: Component of CDC PH Communications for Workforce & Career Development (system UID # 1310)

4. Privacy Act System of Records (SOR) Number: Pending

5. OMB Information Collection Approval Number: 0920-0017 exp. 3/31/2010

6. Other Identifying Number(s): NO

7. System Name: Training and Continuing Education Online (TCEO or TCEOnline, former PHTNonline)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Nancy Gathany (NTC1) [alternate Gary Armstrong (GMA1)]

10. Provide an overview of the system: TCEO system allows health professionals to register and complete requirements to receive continuing education credits. Participants access only their own records. It is a web-based registration system offering continuing education that addresses core competencies, public health issues, public health preparedness and timely updates via distance education and live training events. TCEO includes the following learner support features for participants:

-Technical support through the toll-free 800 number, email box, and on-line information

-Ability to select a downlink site for the satellite broadcast

-Registration for the training event

-Access to the standard course evaluation and exam online

-Ability to view and print transcript and continuing education certificate

TCEO also allows downlink site administration staff to identify and register downlink sites and monitor participant registration.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Participants can access only their own records (for data entry and updates), while only CDC/OD/OWCD Administrators can access login information and reset passwords and view participant contact information (for administration and coordination).

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Name, Mailing Address, Phone Numbers, e-Mail Address, Military Status, Employment Status (all IIF). Collected for providing participants access to training events. All submissions of data are voluntary, and participants only access their own records.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No such changes are contemplated. Should they ever be contemplated, CDC/OD/OWCD Administrators would contact and obtain consent as appropriate by both written and electronic notice.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Admin.: Access only by participants to their own records, or by CDC/OD/OWCD Administrators can access login information and reset passwords and view participant contact information.

Technical: Located in DMZ, passwords are encrypted.

Physical: Mid-tier Data Center under ITSO controls.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 15, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / Etiological Agent Import Permit System (EAIP) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: PIA Validation

1. Date of this Submission: May 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: 09-20-0170

5. OMB Information Collection Approval Number: 0920-0199

6. Other Identifying Number(s): NO

7. System Name: Etiological Agent Import Permit System (EAIP)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Barry Copeland

10. Provide an overview of the system: The Public Health Service Foreign Quarantine regulations (42 CFR 71.54) govern the importation, or subsequent distribution by transfer within the United States, of any etiologic agents, hosts, or vectors of human disease. A permit issued by the CDC, Etiologic Agent Import Permit Program is required for such importations or distributions. The system tracks and issues permits for the international importation of etiologic agents that could be used for bioterrorism purposes. A stand alone desk-top pc system that issues and tracks import permits for select agents.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Division of Quarantine, and any federal agency that needs the data

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Full contact info for the person transferring select (or non-select) agents. Information submission is mandatory

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The information collected by the EAIP program will be submitted (as identified in 42 C.F.R. Part 74, 7 C.F.R. Part 331, and 0 C.F.R part 121) through the submission of CDC-APHIS forms 1-5

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All controls mandated for a HIGH FIPS 199 system are implemented. The system and supporting paper documents are located within secure spaces compliant with Defense Security Services (DSS) standards. All personnel with access to the data will have current DoD Secret level clearances (or equivalent).

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 12, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / MCTA Contracts (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Aug 23, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1510

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: MCTA Contract

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: The Management Consultation and Technical Assistance contract tracks all task orders from pre-award to post award. It also provides reports to management. This system will not change in the future.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Contract related rules and regulations, definitions, and forms only.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / PWS-AT (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 19, 2007

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1516

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: PWS/AT Change Request

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: The Performance Work Statement/Agency Tender (PWS/AT) Change Request System is an electronic navigational tool to aid Most Efficient Organization (MEO) project officers and program managers through the process of documenting growth and/or reductions of a MEO. This system allows for all changes and supporting justification to be documented and approved electronically. The system expedites the review and approval process and also facilitates centralized records management for the MEO Implementation Advisor and the CDC Contract Officer.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Statement of work changes and agency tender changes

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: N/A

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: N/A

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Alice M. Brown

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date:

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / Signature Log (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 13, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-06-02-9409-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Signature Log

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kimberly Thurmond

10. Provide an overview of the system: Signature Log keeps track of all documents signed by the MASO director, as well as those documents presented to but not signed by the MASO director. The system also stores downloadable copies of the signed documents.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: This system does not collect information. It keeps track of all documents signed by the MASO director.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 12, 2008

Date Published: Sept 8, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DVH NCHHSTP Hepatitis Reference Laboratory Data Management System (HRL DMS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Oct 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Hepatitis Reference Laboratory Data Management System (HRL DMS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Saleem Kamilli PhD

10. Provide an overview of the system: The Data Management System is a lab information system in the Hepatitis Reference Laboratory, DVH, NCHHSTP, CDC. It collects, analyzes, stores and report test results in the lab. The system implements the data processing rules from various venders for each analytes of different hepastitis viruses, and uses quality control algorithms to ensure the data are sound. Lab technicians log samples, enter results to the system; lab supervisors configure the testing methods and manages user accounts; epidemiologists can pull reports from the system and get email notification when results are ready.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

E-Authentication Assurance Level = N/A

Risk Analysis Date = 07/16/2008

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P Madden

Sign-off Date: Nov 3, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OEC DIMES Executive Control Correspondence (ECC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Nov 5, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: 09-20-0055

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Executive Control Correspondence (ECC)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cynthia Clark

10. Provide an overview of the system: Users will use Executive Control Correspondence (ECC) to import electronic documents/files into a workflow, and index them with data and route for review and processing. It will be used to convert paper documents sent to the CDC Directors office into an electronic format. They are placed into electronic folders, and routed via a workflow engine to the appropriate centers for review and response. The response document is then printed signed and returned to the requester. A copy of the folder and contents is saved by the system.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): DIMES is responsible for dissemination and tracking of the information. Shared with all CDC Divisions. Sharing in order to craft a response to the correspondence that has come in.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The information that is collected is voluntary and contains IIF. Individuals (public citizens) submit information to the CDC to voice opinion, concern or have questions. The information that is submitted varies from health and product concerns to submission of invention ideas. The information is then forwarded to Subject Matter Experts (SMEs).

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The information is voluntary and is not requested. There is not a process in place for notification.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: DBA – controls database, system admin controls the electronic files, UserID and Passwords. Documents are not stored in a database. They are stored on a file server.

Network and security controls for the web servers and databases are in place as well as network security monitoring and security audits. The system is only available on the intranet, mitigating the exposure outside the firewall. Access to the system and to specific information is controlled using Windows Integrated Authentication so users have to have a valid and active network profile before they are allowed system access.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Felicia P. Kittles, OCISO C&E PM

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P Madden

Sign-off Date: Nov 6, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC CCHIS mobile.cdc.gov (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 17, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9321-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CCHIS mobile.cdc.gov

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Scott Mullins

10. Provide an overview of the system: Mobile.cdc.gov is a Dot Net 2.0 application that refocuses publically available content for use and access on mobile devices. This application is hosted on the worldwide wireless network (WWWN) and converts existing CDC.Gov pages, via a WAP protocol, upon users entering the URL from a mobile browser. There is no active authentication protocol in place as all media and informational content is updated via CDC.Gov.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 10, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER QPR (QPR) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: QPR (QPR)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Joseph Dell

10. Provide an overview of the system: QPR is a COTS application which helps COTPER track progress against its organizational excellence assessment (OEA) measures and initiatives.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DLS NCEH Dioxin and Persistent Organic Pollutants Laboratory (DOXPOP) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Oct 30, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Dioxin and Persistent Organic Pollutants Laboratory (DOXPOP)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cheryl McClure

10. Provide an overview of the system: In the Dioxin and Persistent Organic Pollutants Laboratory (DOXPOP)s laboratory Dioxin and Persistent Organic Pollutants are measured in serum, plasma, breast milk, or adipose tissue and a comparison of relative response factors generated using isotopically labeled and known native standard concentrations yields individual analyte concentrations with detection limits in the low parts per quadrillion range

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system does not contain IIF.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system does not contain IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The system does not contain IIF.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: The system does not contain IIF.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Oct 30, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Influenza Sentinel Provider Surveillance Network (ISPSN) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9721-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: 0920-0004

6. Other Identifying Number(s): No

7. System Name: Influenza Sentinel Provider Surveillance Network

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Lynnette Brammer

10. Provide an overview of the system: Approximately 2400 physician around the country report each week the total number of patients seen and the number of those patients with influenza-like illness by age group. Data can be entered either by the physician, the state influenza surveillance coordinator, or CDC influenza surveillance staff.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Approximately 2400 physician around the country report each week the total number of patients seen and the number of those patients with influenza-like illness by age group. Summary data only.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 5, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC ITSO ITSOTools (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC ITSO ITSOTools

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Wayne Knight

10. Provide an overview of the system: ITSOTools Homepage is a dynamically controlled and data driven website that is based on the user’s Active Directory authentication and security groups.

The system provides a tertiary level of security by utilizing application data driven security categories and groups. Each user will have a unique set of available information provided on the homepage.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Data collected, disseminated, and/or collected pertains to CDC accountable assets(property), network information, ADP information, and CDC user information without any distinguishing identifiable information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No IIF is collected, disseminated, or maintained in the system.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No Information in Identifiable Form is collected or transmitted.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 10, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Laboratory Sample Track and Reporting System (LSTARS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9221-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Laboratory Sample Track and Reporting System (LSTARS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Robert Jones, PhD, Business Steward

10. Provide an overview of the system: The purpose of LSTARS is to collect sample information and track samples and report laboratory test results. LSTARS associates test results and other data with a given specimen. It electronically collects information from NCEH/DLS Laboratory Information Management Systems and reports specimen information and laboratory results to the Specimen Tracking and Results Reporting System (STARRS) during both routine and emergency public health response events.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No, the system does not contain IIF

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: LSTARS associates test results and other data with a given specimen. It electronically collects information from National Center Environmental Health (NCEH)/Division of Laboratory Sciences (DLS) Laboratory Information Management Systems and reports specimen information and laboratory results to the Specimen Tracking and Results Reporting System (STARRS) during both routine and emergency public health response events. All of the data regarding studies, specimens, and test results are stored indefinitely for future reference. The information does not contain IIF, yet it does contain test results. The test results contain no direct information regarding any of the patients.

The system provides specimen descriptions, specimen test orders, and specimen test results to the following organizations:

· National Center for Environmental Health (NCEH)

· National Institute of Occupational Health and Safety (NIOSH)

· Office of the Director (OD)

· National Center for Health Statistics (NCHS)

CDC and ATSDR Specimen Packaging, Inventory, and Repository (CASPIR)

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No, the system does not contain IIF

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 19, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCHS XyVision

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: May 22, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9421-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: XyVision

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Tommy C. Seibert

10. Provide an overview of the system: This system takes existing documents and packages them for printing at GPO or publication on CDC's internet server. Original data and graphics are entered into the system by three users. These users use the system to edit and prepare a final form electronic document that is packaged into a pdf or other format document and then is manually sent by the user's email to its’ final destination.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No IIF is collected, processed, stored or transmitted by the system. System is used strictly for Public document preparation and release.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: May 22, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OCOO ITSO Mailbox Class Size Tool (MCST) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 22, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OCOO ITSO Mailbox Class Size Tool (MCST)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Doug McClelland

10. Provide an overview of the system: The Mailbox Class Size Tool v1.0 allows approved exception requests to be processed by the Network Technology Branch Messaging Team (NTB/MT). NTB/MT Engineers will be able to use the tool to set the Mailbox Class Size and the changes will then replicate to HHSMail.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF not processed by this tool.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name:

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 22, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD NCEH Public Health Assessments & Health Consultations (PHAHC) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Oct 30, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Public Health Assessments & Health Consultations (PHAHC)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Marianne Hartin

10. Provide an overview of the system: Public Health Assessments & Health Consultations (PHAHC) is a web-based content delivery application that users visiting the CDC/NCEH/ATSDR website can access Public Health Statements (PHAs) and Health Consultations (HCs). These documents are findings and information pertaining to hazardous waste sites the CDC and ATSDR are involved in during the investigation and clean-up process. The application allows a user to select a state from an interactive map or from a page that lists states and regions and generates a list of publications that can be accessed. The content is accessed by the public meaning that anyone of interest in knowing about hazardous waste sites can view findings from a particular site. The public in this case is defined as anyone a public official, health professional, students and/or any concerned citizen. The content, the publications have been approved for public viewing.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system does not contain IIF.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The system does not contain IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: None. PHAHC does not contain IIF // E-Authentication Assurance Level = N/A (Public Access) // Risk Analysis Date = 10/15/2008

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR); OCISO C&A Analyst Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Oct 30, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC WHO Collaborating Laboratories (WCL) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9621-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: 0920-0004

6. Other Identifying Number(s): No

7. System Name: WHO Collaborating Laboratories

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Lynnette Brammer

10. Provide an overview of the system: Approximately 85 U.S. WHO collaborating laboratories report weekly the number of specimens tested for influenza and the number positive by virus type/subtype and patient age group. Labs may transmit summary information via the WCL website or by fax.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Approximately 85 U.S. WHO collaborating laboratories report weekly the number of specimens tested for influenza and the number positive by virus type/subtype and patient age group. Labs may transmit summary information via the WCL website or by fax.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 19, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC YRBSS Survey Data Management System (SDMS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: YRBSS Survey Data Management System (SDMS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: SDMS is the data processing system for the Youth Risk Behavior Survey (YRBS) and the Global School Based Student Health Survey (GSHS). It is used to manage questionnaire documents, edit scanned responses, and generate tabulations and graphs for reports to funded sites. SDMS is a Visual Basic application that accesses a SQL server database; it uses Microsoft Office automation to create reports and graphs, creates and executes SAS and SUDAAN programs for statistical processing, and Crystal Reports to present tabulated results. It is accessible only by authorized personnel and all data reside on a LAN drive or SQL server also accessible only by authorized personnel. No personal identifiers are used in any part of processing or data collection.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: No

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: No

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: No

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Jul 28, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC COTPER OneTeam (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-8121-00

4. Privacy Act System of Records (SOR) Number: 09-20-0169

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: OneTeam

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Josh Giles

10. Provide an overview of the system: OneTeam is a web-based application to help the Coordinating Office for Terrorism Preparedness and Emergency Response (COTPER) Division of Business Services (DBS) track staff and vacancy information for all of COTPER. Developed as an expanded replacement for the COTPER Vacancy Action Tracking System (CVATS), OneTeam will combine the ability to track and report information related to vacancies with tracking and reporting of information related to staff members and positions throughout COTPER.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): No

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The application will collect information base on COTPER Positions (both vacant and occupied). Such data includes, but not limited to: Job Title, Division, Branch, Grade, Job Series, Employee Type (Contractor vs FTE), and General Remarks.

Additional data collected about a vacancy will include: Assigned to (a pre-defined list), Date assigned, the vacancy action, and general comments.

Occupied position will collect the person’s name, email and dated they were assigned to that position.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All information will be stored on the CDC internal network.

Access to OneTeam will be based on the CDC’s Windows Authentication, allowing only a pre-determined list of user access to the system via the CDC Intranet. Physical and additional technical controls are handled by ITSO and OSEP per appropriate C&A security controls.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 20, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH Alcohol Related Disease Indicators (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: DACH Alcohol Related Disease Indicators

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH Block Grant MIS - Success Stories (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: DACH Block Grant MIS - Success Stories

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH BRFSS Survey Operations Support (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DACH BRFSS Survey Operations Support

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Track status of data sets submitted by states.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH Chronic Disease Indicators (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DACH Chronic Disease Indicators

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides online information for chronic disease indicators and related statistics

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr.

Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Bibliography (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Bibliography

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Search tool for BRFSS publications.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Coordinators (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Coordinators

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: State BRFSS coordinators.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Data Systems Course (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Data Systems Course

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: BRFSS training web site.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Modules (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Modules

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Listing of BRFSS questionnaire modules available by state and year.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Prevalence (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Prevalence

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: State BRFSS prevalence data.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: IIF is retained until no longer needed.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Publications (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Publications

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Citation information for official state publications that include BRFSS data, such as Healthy People 2000 reports and newsletters.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Questions (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Questions

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Query of questions from previous BRFSS surveys.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS SMART (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS SMART

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Selected Metropolitan/ Micropolitan Area Risk Trends (SMART) displays BRFSS data for selected metropolitan and micropolitan statistical areas.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS Trends (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS Trends

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Trends data for sixteen negative behaviors or circumstances across gender, age groupings, and states.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - BRFSS WEAT (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - BRFSS WEAT

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Web Enabled Analysis Tool - Cross tabulation and logistic analysis for BRFSS.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - CHAPS Toolkit (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - CHAPS Toolkit

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Searchable listing of community health interventions & programs that address chronic disease & health disparities issues.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - HRQOL (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - HRQOL

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Health Related Quality of Life - Displays health-quality indicator statistics from BRFSS data.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - State of Aging (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - State of Aging

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Reports the health status and health behaviors of U.S. adults aged 65 years and older.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - Steps Resource Center (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - Steps Resource Center

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Searchable listing of resources for Steps program communities.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name:

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GA - Syndemics (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GA - Syndemics

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Listing of health professionals involved with Syndemics research.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH GIS - BRFSS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DACH GIS - BRFSS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Geographical display of BRFSS data.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DACH PRC MIS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-05-02-9022-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DACH PRC MIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: System to record funded Prevention Research Centers research activities.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH Evaluation Tutorials (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH Evaluation Tutorials

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: DASH evaluation training Web site.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH GA - Making it Happen (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH GA - Making it Happen

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Stories of schools and school districts that have implemented innovative strategies to improve the nutritional quality of foods and beverages sold outside of Federal meal programs.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH GA - School Health Education Resources (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH GA - School Health Education Resources

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides user-friendly access to the myriad school health education offerings available from the U.S. Department of Health and Human Services' Centers for Disease Control and Prevention (CDC).

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH GA - SHI (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission:

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH GA - SHI

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Self-assessment and planning tool that schools can use to improve their health and safety policies and programs.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH QADS - Online Surveillance Mgmt (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DASH QADS - Online Surveillance Mgmt

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Collects state data on physical activity, nutrition, tobacco, and HIV indicators.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.:

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH Survey TA (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DASH Survey TA

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides technical assistance services to state and local fundees who are doing the Youth Risk Behavior Survey and the School Health Profiles studies in their state or localities.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH YRBSS Data Dissemination (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH YRBSS Data Dissemination

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Data dissemination of the Youth Risk Behavior Surveillance program.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DCPC GA - Atlas (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DCPC GA - Atlas

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Interactive version of The Cancer Atlas publication.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DASH YRBSS Data Dissemination (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DASH YRBSS Data Dissemination

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Data dissemination of the Youth Risk Behavior Surveillance program.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DCPC GA - Program Contacts (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DCPC GA - Program Contacts

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Contact information for CDC's Breast and Cervical Cancer Early Detection Program.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DCPC GA - State Cancer Facts (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s):

7. System Name: DCPC GA - State Cancer Facts

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Shows information for new cancer cases and deaths by state for the most common cancers.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DCPC USCS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DCPC USCS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides state-specific and regional data for cancer cases diagnosed and cancer deaths.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DDT MIS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: DDT MIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DDT Surveillance Trends Reporting System (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DDT Surveillance Trends Reporting System

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Documents trends in diabetes incidence, prevalence and mortality, identifies high-risk groups and evaluates progress in diabetes prevention and control.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DHDSP GIS - DHDSP (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DHDSP GIS - DHDSP

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Geographical display of cardiovascular mortality data.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DHDSP GIS - DHDSP Policy Maps (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DHDSP GIS - DHDSP Policy Maps

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Geographical display of cardiovascular-related legislation.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DHDSP HDSP MIS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-0

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: DHDSP HDSP MIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DHDSP Legislative Database (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: No cost involved; No ESC entry

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DHDSP Legislative Database

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Search for state-level bills related to heart disease and stroke prevention topics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - 5-A-Day Recipes (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA - 5-A-Day Recipes

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Calculator to help determine the amount of fruit and vegetable consumption based on gender and age.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - 5-A-Day Surveillance (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA - 5-A-Day Surveillance

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Analyze and compare survey responses by state, year, and demographic group.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - Abstraction (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA – Abstraction

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Used to gather public study abstracts and the data that supports those studies.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - BMI (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA – BMI

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Calculator to help determine Body Mass Index.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - DNPA Qualitative Research Inventory (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 22, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA - DNPA Qualitative Research Inventory

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides information about qualitative research that has been conducted in the fields of nutrition, physical activity, and other related fields.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - DNPA Program Directory (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: DNPA GA - DNPA Program Directory

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Provides information about physical activity programs involving state departments of health.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - PA Statistics (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 22, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DNPA GA - PA Statistics

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Displays physical activity-related BRFSS data.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - US PA Guidelines (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 23, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DNPA GA - US PA Guidelines

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DNPA GA - Legislative Database (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 22, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DNPA GA - Legislative Database

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Search for state-level bills related to nutrition and physical activity topics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH ASTDD State Synopses (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: DOH ASTDD State Synopses

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH DOH MIS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH MIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Tracks objectives and activities of state based oral health programs.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH GA - My Water's Fluoride (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 23, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH GA - My Water's Fluoride

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH GIS - DOH (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 23, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH GIS – DOH

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Geographical display of oral health indicators and preventive interventions for oral health.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH Oral Health Data Resource Center (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 24, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH Oral Health Data Resource Center

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Serves as a resource on dental, oral and craniofacial data for the oral health research community, clinical practitioners, public health planners and policy makers, advocates and the general public.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH PTS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH PTS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Aids in the tracking and reporting of test data from participating water fluoride testing labs.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DOH WFRS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DOH WFRS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Collects water fluoridation information from public water treatment systems.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH GIS - DRH (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 24, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH GIS – DRH

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Geographical display of reproductive health issues such as infant mortality, fertility, and low birth weight.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH NASS - ART Report 2001 (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH NASS - ART Report 2001

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Online success rates for reproductive fertility technology and clinics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH NASS - ART Report 2002 (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH NASS - ART Report 2002

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Online success rates for reproductive fertility technology and clinics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH NASS - ART Report 2003 (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH NASS - ART Report 2003

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Online success rates for reproductive fertility technology and clinics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28. 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH NASS - ART Report 2004 (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH NASS - ART Report 2004

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Online success rates for reproductive fertility technology and clinics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC DRH NASS - ART Report 2005 (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC DRH NASS - ART Report 2005

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Online success rates for reproductive fertility technology and clinics.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCBDDD EHDI HSFS - Reports (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-08-02-1347-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC NCBDDD EHDI HSFS – Reports

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Reports related to Early Hearing Detection and Intervention.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCHHSTP STD Training Websites (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 17, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: N/A - Mitigation of an issue is due to be completed by 9/27/2008.

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: STD Training Websites

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Rheta Barnes

10. Provide an overview of the system: The system is a set of two web sites used for training in sexually transmitted diseases' control and prevention. One site requires users to login with a userID and password because of the graphic nature of the subject matter. All content is cleared for public release and contains no PII or sensitive information. Below is a more detailed description of the three sites.

STD Curriculum

The STD Curriculum web site is a web-based sexually transmitted disease (STD) curriculum. Seven STD modules are available for clinicians (physicians, advance practice nurses, and PAs) who wish to learn more about STDs. Continuing education credits (CMEs, CNEs) are available through the CDC Public Health Training Network. STD Curriculum offers the seven modules in two formats:

1. An online self study version http://www2a.cdc.gov/stdtraining/self-study/default.asp Users navigate through the curriculum modules by selecting "next" or "previous." They also have the opportunity to answer interactive study questions and case studies, and;

2. A downloadable ready to use version for clinician educators to use in classrooms, http://www2a.cdc.gov/stdtraining/ready-to-use/. Educators can download Microsoft Word documents, Microsoft PowerPoint presentations, and pdf files to use in conducting classes

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Does not share or disclose

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: . Records email addresses for use as user ids. Agency does not use or disseminate these addresses.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: Have not changed the system and do not plan to.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Email addresses are stored on a SQL Server inside the firewall and protected by all CDC network protections.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 3, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCIPC Injury ACE MIS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: None Provided by POC

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC NCIPC Injury ACE MIS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Tracks objectives and activities of state based injury programs.

13. Indicate if the system is new or an existing one being modified: Existing17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCPHI User Accountability System (UAS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 18, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-1255-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: User Accountability System (UAS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Kim Hinton

10. Provide an overview of the system: The system is used by the CDC Emergency Operations Center (EOC) to track personnel checking in and/or performing work for the EOC.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): The system does not share or disclose IIF.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: The system stores name and phone number.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: NIST SP 800-53 controls ensure administrative, technical, and physical controls are adequate to protect system information.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 3, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Newborn Screening Quality Assurance Program (NBSQAP) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 17, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-02-02-9221-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Newborn Screening Quality Assurance Program (NBSQAP)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Carol Bell

10. Provide an overview of the system: The Newborn Screening Program conducts quality assurance for state and international laboratories which screen for treatable inherited metabolic diseases in children. Effective screening by states, using dried blood spot (DBS) specimens collected from newborns soon after birth, combined with follow-up diagnostic studies and treatment, helps prevent mental retardation and premature death.

13. Indicate if the system is new or an existing one being modified: New

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): NBSQAP does not share or disclose IIF information. Only the partner can view its own information.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: NBSQAP uses partner identifier (name) and a non-personal email address to exchange test results. No records are collected by the system. NBSQAP is not an average system; all communications are between non-personal mailboxes.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Yes. See attached E-Auth Appendix to the BSI.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 5, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NOPHG Family Healthware (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC NOPHG Family Healthware

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Demo-version of a tool to be used to assess a person’s familial risk for six diseases (coronary heart disease, stroke, diabetes, and colorectal, breast, and ovarian cancer). It provides users with a “prevention plan” containing personalized recommendations for lifestyle changes and screening.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD GA - Burden Book (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OD GA - Burden Book

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Displays information by state on the burden of heart disease, stroke, cancer and diabetes; causes of death; risk factors among adults and high school students; and preventive services.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD GA - Email Form (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OD GA - Email Form

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Allows the contents of Web pages to be e-mailed.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD NCCDPHP Conference Planning System (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 8, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-01-02-1055-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: OD NCCDPHP Conference Planning System

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system:

Allows coordinators for the Chronic Disease conference to plan agenda, speakers, travel, and other information.

These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH CAPS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH CAPS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - Cessation Resource Center (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA - Cessation Resource Center

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - FAQ (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA – FAQ

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - GYTS Datasets (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA - GYTS Datasets

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - Health Consequences SGR Database (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA - Health Consequences SGR Database

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - Involuntary Smoking SGR Database (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA - Involuntary Smoking SGR Database

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GA - Smoking and Health Resource Library (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GA - Smoking and Health Resource Library

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH GIS - OSH (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 10, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH GIS – OSH

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

\PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH MCRC (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH MCRC

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH NATIONS (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 25, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9023-00

4. Privacy Act System of Records (SOR) Number: n/a

5. OMB Information Collection Approval Number: n/a

6. Other Identifying Number(s): n/a

7. System Name: OSH NATIONS

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: These are authenticated applications on the CoCHP Internet Platform. The logins or user account information contains business IIF. The CoCHP Internet Platform provides dynamic web content to the general public and public health partners in support of the Coordinating Centers for Health Promotion.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris (CTR)

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH NTCP Chronicle (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OSH NTCP Chronicle

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Collects information on state tobacco control programs.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH QIT (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OSH QIT

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Categorizes tobacco-related survey questions.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s):

Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory:

Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH SAMMEC (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OSH SAMMEC

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Calculates economic impacts of smoking.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH SAMMEC - Survey (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 26, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9024-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OSH SAMMEC – Survey

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Satisfaction survey for SAMMEC.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OSH STATES (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 29, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-03-02-9121-00

4. Privacy Act System of Records (SOR) Number: N/A

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: CDC OSH STATES

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Cindy Allen

10. Provide an overview of the system: Contains up-to-date and historical state-level data on tobacco use prevention and control; designed to integrate many data sources to provide comprehensive summary data and facilitate research and consistent data interpretation.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Some of the applications provide business contact information for public officials.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Information contained within this system is for the purpose of providing dynamic Web sites to the general public, state and local health departments, prevention research centers, public health officials, and educational institutions in support of CoCHP programs. The platform is designed to host applications that disseminate Low-category, public data and information; provide interactive features to users of the public Web site; and collect Low-category, public-domain data and information from CoCHP’s funded and unfunded partners. All IIF used within applications on this platform are business-related contact information of public officials that are readily available through a variety of public mechanisms and do not compromise an individual’s personal information.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared:

No uniform process in place. Several applications have a process in place to inform users of major changes to the system.

Users are aware of the IIF collected and how it is being used. Users must volunteer their IIF.

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: All of the data, including the IIF, follow the security controls of the EMSSP.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Quarantine Activity Reporting System (QARS) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 3, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

2007 - 009-20-01-02-02-9721-00-110-246

2008 - 009-20-01-02-02-9721-00

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Quarantine Activity Reporting System (QARS)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Martha S. Remis

10. Provide an overview of the system:

The Division of Global Migration and Quarantine (DGMQ) commissioned the development of a Quarantine Activity Reporting System (QARS) as a subset of the DGMQ Intranet project, as a way to boost internal communications within the division and enable the DGMQ to track the activities recorded in this application.

Currently, each of the eight quarantine stations produces a daily activity report (DAR) of the significant activities occurring at their stations. These reports are then sent to DQ Headquarters, where DGMQ personnel review and consolidate all reports into a Quarantine Activity Daily Report for distribution at the CDC center level and above.

The quarantine stations are involved on a daily basis in various activities, including responding to reports of ill passengers, inspecting imported shipments of nonhuman primates, and monitoring the arrival of immigrants and refugees. These activities are recorded and summarized individually at each quarantine station. Monthly, counts of activities are submitted by each station for a monthly activity report.

The QARS will allow the Quarantine Station personnel to enter their daily activities in an electronic standardized format, using controlled vocabulary. The QARS allows both Quarantine Station personnel and Headquarters personnel to enter follow-up reports to responses and investigations, as well as information gathered after the creation of the initial report. The QARS will enable DGMQ personnel to generate the Quarantine Daily Activity Report in a timelier and uniform manner. The information collected on a daily basis will be collated and stored in a database that can be utilized to generate reports on a monthly, quarterly, and annual basis. The system will facilitate the provision of required data for the Office of Management and Budget. The QARS will allow for the assessment of the volume and type of activities that the quarantine stations perform in order to better allocate resources and personnel. The information gathered through the illness investigation reports will enable the quantification and analysis of the information acquired during illness responses and investigations.

It is envisioned that the QARS system will interface with other DGMQ systems such as

· E-Manifest application-to facilitate the inclusion of lists of exposed passengers derived from airplane manifests

· MOATS application – facilitate the invocation of MOA and sending persons to correct MOA hospitals as well as supplying the MOATS application with the correct passenger information.

· GeoSentinel application - enabling analysis on the information gathered in QARS and the Geo-sentinel application to produce reports of disease pattern recognition.

· EDN, Electronic Disease Notification application – to prevent the double entry of immigration and refugee information.

In Release 1, the ill passenger and investigation process has been automated as well as the importation of non-human primates. The interaction with the MOATS and E-Manifest applications will be manual. In release 1, limited reporting will be available. The system will provide information to generate the Daily Activity Report though.

In Release 2, the land border crossings portion in paper form will be developed and piloted at land border crossings. The Active Surveillance portion of the Quarantine station daily activities reporting has been added.

During the period, that Release 2 is developed the change request received from the users in the quarantine stations and head quarters will be evaluated for inclusion in Release 2 following the formal Change Request process as defined by the NCID UP, Unified Process.

Release 3 added the following types of reports:

· Partnership Activities – the activities a quarantine station conducts on a regular basis with outside partners can be reported using this module.

· Drug dispersements – the quarantine stations disperse anti-toxin to hospitals, pharmacies, and private physicians in the US and abroad. The quarantine station user uses this module to record anti-toxin dispersements.

· Anti-toxin drug inventory management tools – this module allows for tracking of transfers to and from the quarantine stations, managing of re-supply levels, managing the types of anti-toxin the quarantine stations can disperse as well as the lot # of these drugs.

· Land border crossing – the paper form developed during Release 2 was automated.

· Countries of interest management tool – There are certain countries that are of interest to CDC. The QARS system flags reports that reference those countries as country of origin, country visited, country traveled.

· Accompanying reports

Release 4 added the following functionality:

· Refugee/Asylee packet processing

· Immigrant/K+V-visa/parolee packet processing

· Active Surveillance update for pandemic flu

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion

21. Is the system subject to the Privacy Act?: No

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): DGMQ quarantine station public health officers, medical officers, head quarter staff to perform duties as required by regulations.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Mandatory. Information is used to follow up with ill passengers, trace contacts or inform exposed persons of possible exposure.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: None

32. Does the system host a website?: Yes

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: No

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: HHS ROB, ITSO managed system. C&A in process.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 25, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC Auto Decal (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Sep 9, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 009-20-01-06-02-0984-00

4. Privacy Act System of Records (SOR) Number: DOT/ALL8

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): N/A

7. System Name: Auto Decal

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Tracy Hollis

10. Provide an overview of the system: Mainframe application used by the Office of Security and Emergency Preparedness to issue car decals for any vehicles parked on CDC premises or leased property by CDC workforce. The only system users are OSEP personnel, who enter information regarding a vehicle and the associated decal number and the owner’s User ID. The information is manually typed from a signed form by the vehicle owner usually submitted to security personnel assigned to the user’s workplace. The security staff issues the decal, and then submits the form to the security office in charge of entering the information from the form. This may take several days from the time the user is issued a decal until the information is entered into the Auto Decal system.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): N/A

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory: Mainframe application used by the Office of Security and Emergency Preparedness to issue car decals for any vehicles parked on CDC premises or leased property by CDC workforce. The information collected is User ID and Vehicle Identifiers. The only system users are OSEP personnel, who enter information regarding a vehicle and the associated decal number and the owner’s User ID. The information is manually typed from a signed form by the vehicle owner usually submitted to security personnel assigned to the user’s workplace. The security staff issues the decal, and then submits the form to the security office in charge of entering the information from the form. This may take several days from the time the user is issued a decal until the information is entered into the Auto Decal system. The information is voluntary but mandatory for an Auto Decal.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: No

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Need to Know policy is enforced in the application. Only designated OSEP personnel can see the record. User Id’s, Passwords (expire after a set period of time), Accounts are locked after a set period of inactivity, Minimum length of passwords is eight characters, Accounts are locked after a set number of incorrect attempts. Firewall protected.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Aug 19, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC NCHS Automated Tracking System (NCHSAT) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: No

If this is an existing PIA, please provide a reason for revision: Internal Flow or Collection

1. Date of this Submission: Sep 30, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number: 1329

4. Privacy Act System of Records (SOR) Number: 09-20-0164

5. OMB Information Collection Approval Number: N/A

6. Other Identifying Number(s): ESC ID = 197

7. System Name: CDC NCHS Automated Tracking System (NCHSAT)

9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Chris Cox

10. Provide an overview of the system: The NCHS Automated Tracking System (NCHSAT) is a GUI driven data management system which supports the address tracking of NCHS survey participants. Participant names and addresses are matched with United States Postal Service (USPS) address information files and/or National Change of Address Link (NCOALink) database to collect information about participant migration and to collect updated address information. This system assists NCHS with re-contacting survey participants to conduct follow-up survey activities and to improve the data quality of administrative records data linkage projects.

The data collection activity is authorized by Section 308(d) of the Public Health Service Act (42 U.S.C. 242m(d)) All information obtained will be held strictly confidential and will be used for statistical research purposes only.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: YesNote: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

21. Is the system subject to the Privacy Act?: Yes

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Data in the NCHS Automated Tracking System are used by the OAE Special Projects Branch and the NCHS survey owners for statistical purposes.

Survey participant name and mailing address is sent to the National Change of Address Link (NCOALink) and/or to Postmasters employed by the US Postal Service to confirm or obtain updated name and address information.

The data contained within the NCHSAT is not shared with any other persons within NCHS or external to NCHS.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory:

As the Nation’s principal health statistics agency, NCHS compiles statistical information to guide actions and policies to improve the health of the nation. To carry out this mission NCHS conducts several major national health surveys designed to collect data about the health status and health behaviors of the nation’s population. During the conduct of these surveys, respondents are informed that their participation is voluntary and that they may refuse to answer any questions. Survey respondents are informed about the planned uses of the data and as part of the interview process are asked to provide personal identification information. Names and addresses of subject survey respondents, collected during respondent interviews are loaded into the NCHS Automated Tracking system at the completion of the active data collection period. The NCHSAT system is used to update name and address information through NCHS approved data collection and verification activities. These activities involve matching current name and address information to the National Change of Address Link (NCOALink) database and/or contacting Postmasters employed by the US Postal Service to confirm name and address information for current residents.

NCHS conducts survey participant tracking for two reasons: 1) to assist in re-contacting survey participants to conduct follow-up survey activities and 2) to improve the data quality of administrative records data linkage projects. Longitudinal follow-up studies provide a tool to measure health outcomes and to observe the natural history of diseases. By passively tracking survey respondent migration, NCHS reduces costs and increases survey response rates for key data collection activities. Administrative record linkage projects serve to increase the analytic potential of NCHS population based health surveys for epidemiologic research by linking exposures to health outcomes (such as mortality) and increasing the accuracy and level of detail of health data. Using the NCHSAT to collect accurate name and address information increases the accuracy of linking survey respondents to the correct administrative record, reduces the cost of survey respondent re-location after the initial survey contact, and results in less attrition in both longitudinal and linkage data collection efforts which improves the scientific value of the data. Updating name and address information is the minimum activity necessary to locate survey respondent current residence.

The activities of the NCHS Automated Tracking system support DHHS strategic goal 4 – Scientific Research and Development Objective 4.2 Increase Basic Scientific knowledge to improve human health and development.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: NCHS obtains verbal notice of consent from survey participants to collect IIF. NCHS survey participants are always notified through the informed consent process that the provision of IIF is voluntary. The informed consent process informs survey participants of the intended uses of the data and the legislative requirements placed on NCHS to protect survey participant’s confidentiality. NCHS Ethics Review Board requirements do not allow NCHS to deviate from the intended uses of IIF provided in the informed consent process. Section 308(d) of the Public Health Service Act (42 U.S.C. 242m(d)) prevents NCHS from disclosing identifiable information collected from survey participants for any use other than statistical research.

32. Does the system host a website?: No37. Does the website have any information or pages directed at children under the age of thirteen?: No

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?: Yes

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: Forms collected from the Post Office and CDs collected from NCOA are destroyed after being entered and updated in the system. The data stored in the NCHSAT will be retained until the NCHS survey is retired. At the point of each survey’s retirement, the data stored in the NCHSAT for that survey will be deleted.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Sep 3, 2008

Date Published: Nov 28, 2008

 

06.3 HHS PIA Summary for Posting (Form) / CDC OD NCIPC Media Database (MediaDB) (Item)

 

PIA SUMMARY AND APPROVAL COMBINED

 

1

 

PIA Summary

 

Is this a new PIA 2008?: Yes

If this is an existing PIA, please provide a reason for revision:

1. Date of this Submission: Oct 30, 2008

2. OPDIV Name: CDC

3. Unique Project Identifier (UPI) Number:

4. Privacy Act System of Records (SOR) Number: No

5. OMB Information Collection Approval Number: No

6. Other Identifying Number(s): No

7. System Name: Media Database (MediaDB)9. System Point of Contact (POC). The System POC is the person to whom questions about the system and the responses to this PIA may be addressed: Sarah (Gail) Hayes

10. Provide an overview of the system: Media Database (MediaDB) is an internal non-web based MS Access Database that provides NCIPC with the ability to keep electronic records of daily media contacts regarding ongoing research involving CDC public health issues. When a reporter or news columnist contacts the CDC for further information regarding public health issues, the media reporter provides the CDC with a business e-mail address and business phone number of the media reporter. The CDC spokesperson can then return the call to relay any research information that the CDC has gathered that the CDC personnel deems appropriate. This is the only Personable Identifiable Information (PII) in turn that is tracked in MediaDB.

13. Indicate if the system is new or an existing one being modified: Existing

17. Does/Will the system collect, maintain (store), disseminate and/or pass through IIF within any database(s), record(s), file(s) or website(s) hosted by this system?: Yes

Note: This question seeks to identify any, and all, personal information associated with the system. This includes any IIF, whether or not it is subject to the Privacy Act, whether the individuals are employees, the public, research subjects, or business partners, and whether provided voluntarily or collected by mandate. Later questions will try to understand the character of the data and its applicability to the requirements under the Privacy Act or other legislation

Note: If no IIF is contained in the system, please answer questions 21, 23, 30, 31, 37, 50 and 54, then promote the PIA to the Sr. Privacy Official who will authorize the PIA.

If this system contains IIF, all remaining questions on the PIA Form Tabs must be completed prior to signature and promotion.

23. If the system shares or discloses IIF please specify with whom and for what purpose(s): Only MediaDB team members are allowed to view any business contact information.

30. Please describe in detail: (1) the information the agency will collect, maintain, or disseminate; (2) why and for what purpose the agency will use the information; (3) In this description, indicate whether the information contains IIF; and (4) whether submission of personal information is voluntary or mandatory:

MediaDB stores business e-mail address and phone numbers of various media reporter personnel.

31. Please describe in detail any processes in place to: (1) notify and obtain consent from the individuals whose IIF is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changed since the notice at the time of the original collection); and (2) notify and obtain consent from individuals regarding what IIF is being collected from them and how the information will be used or shared: The media reporter will contact the CDC to obtain information regarding CDC public health research matters. The reporter will leave contact information with the CDC, so that the CDC can contact the person should new information become available.

32. Does the system host a website?: No

37. Does the website have any information or pages directed at children under the age of thirteen?:

50. Are there policies or guidelines in place with regard to the retention and destruction of IIF?:

54. Briefly describe in detail how the IIF will be secured on the system using administrative, technical, and physical controls.: MediaDB has one system administrator who has full privileges.

PIA Reviewer Approval: Promote

Comments:

PIA Reviewer Name: Michael W. Harris

Sr. Official for Privacy Approval: Promote

Comments:

Sr. Official for Privacy Name: Thomas P. Madden

Sign-off Date: Oct 30, 2008

Date Published: Nov 28, 2008