Download:
pdf |
pdfSave
Privacy Impact Assessment Form
v 1.47.4
Status Draft
Form Number
F-39931
Form Date
Question
Answer
1
OPDIV:
CDC
2
PIA Unique Identifier:
P-7301860-028835
2a Name:
11/29/2017 1:11:45 PM
National Environment Public Health Tracking Network
(NEPHTN)
General Support System (GSS)
Major Application
3
Minor Application (stand-alone)
The subject of this PIA is which of the following?
Minor Application (child)
Electronic Information Collection
Unknown
3a
Identify the Enterprise Performance Lifecycle Phase
of the system.
Operations and Maintenance
Yes
3b Is this a FISMA-Reportable system?
4
Does the system include a Website or online
application available to and for the use of the general
public?
5
Identify the operator.
6
Point of Contact (POC):
7
Is this a new or existing system?
8
Does the system have Security Authorization (SA)?
8b Planned Date of Security Authorization
No
Yes
No
Agency
Contractor
POC Title
Computer Scientist
POC Name
Patrick Wall
POC Organization ONDIEH/NCEH/DEHHE/EHTB
POC Email
paw8@cdc.gov
POC Phone
770-488-3819
New
Existing
Yes
No
December 15, 2017
Not Applicable
Page 1 of 4
Save
11 Describe the purpose of the system.
The CDC's National Environmental Public Health Tracking
Network (NEPHTN) was created in order to better understand
the connection between health and the environment.
NEPHTN is a dynamic, web-based data system that CDC, its
partners, and community members use to track environmental
health factors over time and improve the health of
communities.
NEPHTN deals specifically with non-infectious diseases and
other health effects that may be associated with
environmental exposures. Health effects may include: birth
defects, developmental disabilities, asthma and chronic
respiratory disease, cancer, and neurological diseases.
Environmental factors included in NEPHTN include chemicals,
physical agents, biomechanical stressors, and biological toxins.
NEPHTN is a system of integrated health, exposure and hazard
data from a variety of national, state and city sources. It deals
specifically with non-infectious diseases and other health
effects that may be associated with environmental exposures,
for example: Air Quality, Asthma, Birth Defects, Cancer, Carbon
Monoxide Poisoning, Childhood Lead Poisoning, Climate
Change, Pesticides, Water Systems and Heart Attacks. To this
end, NEPHTN collects and stores de-identified, demographic
data regarding:
Describe the type of information the system will
collect, maintain (store), or share. (Subsequent
12
questions will identify if this information is PII and ask
about the specific data elements.)
Health conditions and diseases, e.g., asthma and heart disease;
Contaminants in the environment, such as pollution in the air;
Climate, like extreme heat events;
Community design, e.g., access to parks;
Behaviors, like smoking; and
Population characteristics, such as age and income.
NEPHTN presents its data via public and secure web portals.
The public portal is accessible to the general public and does
not require authentication. The secure portal is accessible to
vetted federal, state and local partners only. Internal users
authenticate via Active Directory/PIV credentials for access to
the system. External users are authenticated through the
Secure Access Management System (SAMS) using a User ID
and password or a SAMS card. User identification/
authentication information is not stored in the system.
Page 2 of 4
Save
Provide an overview of the system and describe the
13 information it will collect, maintain (store), or share,
either permanently or temporarily.
NEPHTN is a system of integrated health, exposure and hazard
data from a variety of national, state and city sources. It
displays environmental health data in a format that is easy to
understand and use, enabling users to create customized
maps, tables, and charts of local, state, and national data.
NEPHTN's data is contributed by state and local health
departments that CDC funds to: (1) Collect environmental
health data in their communities; (2) Develop local tracking
networks for their health departments; and (3) Share data with
CDC. The data also comes from national sources, like other
federal agencies and national organizations. The system's data
is helpful for various user types. For instance:
Individuals can use the data to discover what environmental
health issues are important in their communities;
Public health professionals can access data to monitor trends
and help design programs or needs assessments;
Health care professionals can advise patients based on
environmental and health data specific to their community;
and
Decision makers can use the data to inform health policy.
All data collected and stored within NEPHTN is nonidentifiable.
There are two portals: A public access portal, which does not
require users to identify or authenticate; and a secure access
portal, requiring internal users to authenticate via Active
Directory and PIV while external users authenticate via SAMS.
Yes
14 Does the system collect, maintain, use or share PII?
39 Identify the publicly-available URL:
40 Does the website have a posted privacy notice?
No
http://ephtracking.cdc.gov/
https://ephtsecure.cdc.gov/
Yes
No
40a
Is the privacy policy available in a machine-readable
format?
Yes
41
Does the website use web measurement and
customization technology?
Yes
42
Does the website have any information or pages
directed at children under the age of thirteen?
Yes
43
Does the website contain links to non- federal
government websites external to HHS?
Yes
Is a disclaimer notice provided to users that follow
43a external links to websites not owned or operated by
HHS?
Yes
No
No
No
No
No
Page 3 of 4
Save
General Comments
OPDIV Senior Official
for Privacy Signature
Beverly E.
Walker -S
Digitally signed by
Beverly E. Walker -S
Date: 2017.12.21 18:17:49
-05'00'
Page 4 of 4
File Type | application/pdf |
File Modified | 2017-12-21 |
File Created | 2016-03-30 |