Privacy Impact Assessment (PIA)
CMS requires Privacy Impact Assessments for systems handling sensitive data. Business Owners and ISSOs must complete them for new or changed systems. PIAs ensure privacy compliance and are published for transparency.
Last Reviewed: 1/30/2025
All completed PIAs (including TPWA PIAs) for CMS systems are posted online to offer transparency to the public. View CMS PIAs here.
What is a Privacy Impact Assessment (PIA)?
A Privacy Impact Assessment (PIA) is an analysis of how personally identifiable information (PII) is collected, used, shared, and maintained. The PIA demonstrates that Business/System owners have consciously incorporated privacy protections into their systems to safeguard information supplied by the public.
PIAs are required by the E-Government Act of 2002, which improves the management of Federal electronic government services and processes. Section 208 of the E-Government Act specifically requires PIAs to be created when a federal agency develops or procures new information technology that involves the collection, maintenance, or dissemination of information in identifiable form.
Because the E-Government Act also includes a provision requiring PIAs to be published publicly on agency websites, they also support transparency and accountability to the public. At the Centers for Medicare & Medicaid Services (CMS), we publish PIAs on CyberGeek (see the full PIA list here) to comply with the E-Government Act and to communicate with the public about how we address privacy concerns and safeguard sensitive information.
Why are PIAs important?
PIAs are more than a document — they are a process intended to give visibility into privacy risks and identify optimal ways of protecting personal information. PIAs are important because they help Business Owners and system teams:
- Determine the risks of creating, collecting, using, processing, storing, maintaining, disseminating, disclosing, and disposing of PII within FISMA systems.
- Examine and evaluate protections for handling information to mitigate potential privacy concerns.
- Develop new solutions to manage PII if current collection methods aren’t optimized.
- Ensure that information is handled in a manner that supports all applicable legal, regulatory, and policy requirements regarding privacy.
Who completes PIAs?
Privacy Impact Assessments (PIAs) are a team effort. The Information System Security Officer (ISSO) leads the effort on behalf of the Business/System Owner to assess the privacy safeguards and complete the PIA questionnaire in CFACTS. To ensure accurate completion of the PIA, the ISSO receives support from experts within the CMS Information Security and Privacy Group (ISPG), which may include:
- Division of Security, Privacy, Policy & Oversight (DSPPO)
- Cyber Risk Advisors (CRAs)
- Privacy Advisors
After the PIA is completed by CMS system stakeholders, it is reviewed and signed by privacy staff at the U.S. Department of Health and Human Services (HHS).
Third Party Website and Applications (TPWAs)
What is a Third Party Website and Application (TPWA)?
A Third Party Website and Application (TPWA) refers to web-based technologies that are not exclusively operated or controlled by a government entity, or that involve significant participation of a non-government entity. These technologies are often located on a .com website or domain that is not part of an official government domain. However, third-party applications can also be embedded or incorporated on an agency's official website.
Common examples of TPWAs include:
- Social media platforms (e.g., Facebook, Instagram, LinkedIn, Twitter/X)
- Video sharing platforms (e.g., YouTube)
- Photo sharing platforms (e.g., Flickr)
- Blog and microblogging tools
- Other web-based engagement tools used to communicate with the public
CMS uses TPWAs to communicate with and engage the public for program purposes and to implement the principles of the Open Government Directive.
Open Government Directive Principles
| Principle | Description |
| Transparency | Providing the public with information about what an OPDIV is doing by making it available online in an open medium or format that can be retrieved, downloaded, indexed, and searched by commonly used applications. |
| Participation | Enabling the public to contribute ideas and expertise so that an OPDIV can make policies with the benefit of information that is widely dispersed in society. |
| Collaboration | Encouraging partnerships and cooperation with other Federal and non-Federal governmental agencies, the public, and non-profit and private entities to fulfill the OPDIV's core mission activities. |
What is a TPWA Privacy Impact Assessment (PIA)?
A TPWA Privacy Impact Assessment (PIA) is a formal assessment mechanism used by federal agencies to evaluate their use of third-party websites and applications to ensure that such uses protect individual privacy.
Per OMB Memorandum M-10-23, Guidance for Agency Use of Third-Party Websites and Applications, federal agencies are required to:
- Assess their use of third-party websites and applications for privacy implications
- Complete and maintain PIAs for all applicable TPWAs in use
- Make completed PIAs publicly available upon completion
Similar to standard agency-specific PIAs, Operating Divisions (OPDIVs) — including CMS — are responsible for completing and maintaining PIAs on all third-party websites and applications in use, in accordance with HHS policy.
Important Note: Websites and applications operated on behalf of CMS by a third-party contractor are not automatically categorized as a TPWA solely because they are operated by a third-party contractor. In order to qualify as a TPWA, the use of the website or application must meet the additional categories described in this document.
When Can I Use a Third Party Website or Application?
Before using a TPWA, you must complete the following steps:
- Have a valid business reason for the use of the TPWA.
- Obtain approval from your management prior to creating an account or deploying the TPWA.
- Check the HHS approved list of TPWA PIAs page on CyberGeek for a TPWA that may already have been completed by CMS.
- If an approved PIA does not exist, complete the TPWA PIA checklist (see Section 4) to determine whether a new TPWA PIA is needed.
If it is determined that a TPWA PIA is needed, contact the CMS Privacy Office to obtain the TPWA PIA template to assess privacy and security risks for the use of the TPWA.
How Do I Determine If I Need a TPWA PIA?
Question 1
Is the website or application part of authorized law enforcement, national security, or intelligence activities?
- ✅ Yes — Stop here. You do not need to complete a TPWA PIA.
- ➡️ No — Continue to Question 2.
Question 2
Is the website or application used for internal activities that do not involve the public?
- ✅ Yes — Stop here. You do not need to complete a TPWA PIA.
- ➡️ No — Continue to Question 3.
Question 3
Does CMS own, operate, or control the website or application?
- ✅ Yes — Stop here. You do not need to complete a TPWA PIA. However, an IT System PIA is likely needed.
- ➡️ No — Continue to Question 4.
Question 4
Does another Federal department or agency own, operate, or control the website or application?
- ✅ Yes — Stop here. You do not need to complete a TPWA PIA.
- ➡️ No — Continue to Question 5.
Question 5
Does the website or application (e.g., Facebook, YouTube) obtain funding from the Federal Government, or does it exist solely because of the significant participation of the Federal Government?
- ✅ Yes — Stop here. You do not need to complete a TPWA PIA.
- ➡️ No — Continue to Question 6.
Question 6
Is the website or application used by the OPDIV to engage with the public in support of the principles (transparency, participation, and collaboration) of the Open Government Directive?
- ✅ Yes — Complete a TPWA PIA.
- ❌ No — The website or application does not require a TPWA PIA.
Decision Tree Summary
| Question | Topic | Yes | No |
| 1 | Law enforcement / national security / intelligence | Stop — No PIA needed | Continue |
| 2 | Internal use only (no public involvement) | Stop — No PIA needed | Continue |
| 3 | CMS owns, operates, or controls it | Stop — IT System PIA likely needed | Continue |
| 4 | Another Federal agency owns/operates/controls it | Stop — No PIA needed | Continue |
| 5 | Federally funded or exists due to Federal participation | Stop — No PIA needed | Continue |
| 6 | Used to engage public per Open Government Directive | TPWA PIA Required | No PIA needed |
Key Definitions
| Term | Definition |
| TPWA | Third Party Website and Application — a web-based technology not exclusively operated or controlled by a government entity |
| PIA | Privacy Impact Assessment — a formal analysis of how personally identifiable information (PII) is collected, used, shared, and maintained |
| OPDIV | Operating Division — a component agency within HHS, such as CMS |
| Open Government Directive | A federal directive promoting transparency, participation, and collaboration in government operations |
| OMB | Office of Management and Budget — issues federal policy guidance including M-10-22 and M-10-23 |
| IS2P2 | CMS Information Systems Security and Privacy Policy |
References
The following policies and guidance documents govern the use of TPWAs and the TPWA PIA process:
- Circular A-130 — Managing Information as a Strategic Resource (Office of Management and Budget)
- OMB M-10-22 — Guidance for Online Use of Web Measurement and Customization Technologies
- OMB M-10-23 — Guidance for Agency Use of Third-Party Websites and Applications
- CMS Information Systems Security and Privacy Policy (IS2P2)
- HHS OCIO Guidance — Implementation of OMB M-10-22 and OMB M-10-23
For questions regarding the TPWA PIA process, please contact CMS Privacy at privacy@cms.hhs.gov
For additional CMS privacy resources on the privacy impact assessment process, visit us at https://security.cms.gov/learn/privacy-impact-assessment-pia
──────────────────────────────────────────────────
This document is intended for internal CMS use and guidance purposes. All TPWA deployments must comply with applicable federal laws, OMB guidance, and CMS/HHS policies.