AddThis
Date signed: 9/21/2015
| TPWA PIA Questions | TPWA PIA Answers |
|---|---|
| OPDIV: | CMS |
| TPWA Unique Identifier (UID): | T-2541536-196667 |
| Is this a new TPWA? | Yes |
| Please provide the reason for revision. | Not applicable because this is a new assessment of a third party tool. |
| Will the use of a third-party Website or application create a new or modify an existing HHS/OPDIV System of Records Notice (SORN) under the Privacy Act? | No |
| Indicate the SORN number (or identify plans to put one in place.) | Not applicable because CMS is not collecting or storing one or more personally identifiable information (PII) elements |
| Will the use of a third-party Website or application create an information collection subject to OMB clearance under the Paperwork Reduction Act (PRA)? | No |
| Indicate the OMB approval number and approval number expiration date (or describe the plans to obtain OMB clearance.) |
|
| Does the third-party Website or application contain Federal Records? | No |
| Describe the specific purpose for the OPDIV use of the third-party Website or application: | AddThis is a third party email service tool available to individuals who choose to use it, when browsing HealthCare.gov for information about affordable insurance. After obtaining answers to questions regarding health insurance on HealthCare.gov, individuals can click on an icon (an envelope shape located on some website pages) that makes it easy to share information with others using either email or social media. How the tool works on HealthCare.gov: When you find information that is helpful, you can choose to share that information with someone else. To use the AddThis tool to share, click on the envelope shaped icon on a HealthCare.gov page and a screen will appear asking for the following information:
The subject of the email will conveniently pre-populate to identify the topic you are requesting to share. After providing this information and clicking the send button, an email will be sent to the individual that you selected along with a link to the helpful information on HealthCare.gov. When individuals choose to use the AddThis email service tool to share information, AddThis uses this personal information only to send emails on your behalf and uses it for no other purpose. The personal information is not merged or combined with any other information collected by AddThis. Further, AddThis does not share personal information with CMS and CMS does not collect, use, or store personal information provided to AddThis. CMS receives reports from AddThis which are used by CMS to measure what information is the most helpful and to identify how frequently information is shared. The purpose of using this tool and the reports it makes available is to improve the site and to make it more useful to HealthCare.gov visitors. These reports are available only to CMS managers, teams who implement Federally Facilitated Marketplaces programs that are represented on HealthCare.gov, members of the CMS communications and web teams, and other designated federal staff and contractors who require this information to perform jobs with CMS. |
| Have the third-party privacy policies been reviewed to evaluate any risks and to determine whether the Website or application is appropriate for OPDIV use? | Yes |
| Describe alternative means by which the public can obtain comparable information or services if they choose not to use the third-party Website or application: | If consumers do not want AddThis to collect information related to their visits to HealthCare.gov, consumers can not use the content sharing functionality (share-buttons) that is available on most HealthCare.gov articles. Consumers can share HealthCare.gov URLs directly on social media sites or via emails without using our share-buttons. Lastly, a consumer can use the Tealium iQ Privacy Manager on HealthCare.gov's privacy page and "opt out" of having the AddThis tool load during their visit. Tealium iQ Privacy Manager gives site visitors control and choice over which tools and technologies they want to accept and which ones they do not want to accept. |
| Does the third-party Website or application have appropriate branding to distinguish the OPDIV activities from those of nongovernmental actors? | No |
| How does the public navigate to the third party Website or application from the OPIDIV? | The public does not navigate to AddThis. AddThis works in the background. |
| Please describe how the public navigate to the third-party website or application: | The public does not navigate to AddThis. The AddThis tools works when individuals are visiting HealthCare.gov. However, individuals are provided with a link that allows them to access the AddThis website from HealthCare.gov. The link, located on the screen requesting information for emailing purposes, is for the AddThis landing page and is not a government website nor a site owned or operated by CMS. |
| If the public navigate to the third-party website or application via an external hyperlink, is there an alert to notify the public that they are being directed to a nongovernmental Website? | No |
| Has the OPDIV Privacy Policy been updated to describe the use of a third-party Website or application? | Yes |
| Provide a hyperlink to the OPDIV Privacy Policy: | https://www.healthcare.gov/privacy/ |
| Is an OPDIV Privacy Notice posted on the third-party Website or application? | No |
| Is PII collected by the OPDIV from the third-party Website or application? | No |
| Will the third-party Website or application make PII available to the OPDIV? | No |
| Describe the PII that will be collected by the OPDIV from the third-party Website or application and/or the PII which the public could make available to the OPDIV through the use of the third-party Website or application and the intended or expected use of the PII: | CMS does not collect any PII through the use of AddThis. |
| Describe the type of PII from the third-party Website or application that will be shared, with whom the PII will be shared, and the purpose of the information sharing: | PII is not stored or shared. |
| If PII is shared, how are the risks of sharing PII mitigated? | No PII is shared with CMS. |
| Will the PII from the third-party Website or application be maintained by the OPDIV? | No |
| Describe how PII that is used or maintained will be secured: | Not applicable |
| What other privacy risks exist and how will they be mitigated? | CMS' use of AddThis at HealthCare.gov aligns with federal and agency policy because the tool is used solely for the purposes of improving consumers’ services and activities online. To protect privacy and to be transparent about the use of AddThis, other privacy risks have been identified and mitigated:
|
Third-Party Web and Application (TPWA) Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services