Skip to main content

AddThis

Date signed: 9/21/2015

TPWA PIA info for AddThis
TPWA PIA QuestionsTPWA PIA Answers
OPDIV:CMS
TPWA Unique Identifier (UID):T-2541536-196667
Is this a new TPWA?Yes
Please provide the reason for revision.Not applicable because this is a new assessment of a third party tool.
Will the use of a third-party Website or application create a new or modify an existing HHS/OPDIV System of Records Notice (SORN) under the Privacy Act?No
Indicate the SORN number (or identify plans to put one in place.)Not applicable because CMS is not collecting or storing one or more personally identifiable information (PII) elements
Will the use of a third-party Website or application create an information collection subject to OMB clearance under the Paperwork Reduction Act (PRA)?No
Indicate the OMB approval number and approval number expiration date (or describe the plans to obtain OMB clearance.)
  • OMB Approval Number: Not applicable
  • Expiration Date: Not applicable
  • Explanation: OMB clearance is not required because CMS is not collecting information from individuals or entities.
Does the third-party Website or application contain Federal Records?No
Describe the specific purpose for the OPDIV use of the third-party Website or application:

AddThis is a third party email service tool available to individuals who choose to use it, when browsing HealthCare.gov for information about affordable insurance. After obtaining answers to questions regarding health insurance on HealthCare.gov, individuals can click on an icon (an envelope shape located on some website pages) that makes it easy to share information with others using either email or social media.   

How the tool works on HealthCare.gov:  When you find information that is helpful, you can choose to share that information with someone else. To use the AddThis tool to share, click on the envelope shaped icon on a HealthCare.gov page and a screen will appear asking for the following information: 

  • the email address of the person you would like to share information with,
  • your email address, and
  • a message to include in the body of the email. 

The subject of the email will conveniently pre-populate to identify the topic you are requesting to share. After providing this information and clicking the send button, an email will be sent to the individual that you selected along with a link to the helpful information on HealthCare.gov.   

When individuals choose to use the AddThis email service tool to share information, AddThis uses this personal information only to send emails on your behalf and uses it for no other purpose. The personal information is not merged or combined with any other information collected by AddThis. Further, AddThis does not share personal information with CMS and CMS does not collect, use, or store personal information provided to AddThis. 

CMS receives reports from AddThis which are used by CMS to measure what information is the most helpful and to identify how frequently information is shared. The purpose of using this tool and the reports it makes available is to improve the site and to make it more useful to HealthCare.gov visitors. 

These reports are available only to CMS managers, teams who implement Federally Facilitated Marketplaces programs that are represented on HealthCare.gov, members of the CMS communications and web teams, and other designated federal staff and contractors who require this information to perform jobs with CMS.  

Have the third-party privacy policies been reviewed to evaluate any risks and to determine whether the Website or application is appropriate for OPDIV use?Yes
Describe alternative means by which the public can obtain comparable information or services if they choose not to use the third-party Website or application:

If consumers do not want AddThis to collect information related to their visits to HealthCare.gov, consumers can not use the content sharing functionality (share-buttons) that is available on most HealthCare.gov articles. Consumers can share HealthCare.gov URLs directly on social media sites or via emails without using our share-buttons. 

Lastly, a consumer can use the Tealium iQ Privacy Manager on HealthCare.gov's privacy page and "opt out" of having the  AddThis tool load during their visit. Tealium iQ Privacy Manager gives site visitors control and choice over which tools and technologies they want to accept and which ones they do not want to accept. 

Does the third-party Website or application have appropriate branding to distinguish the OPDIV activities from those of nongovernmental actors?No
How does the public navigate to the third party Website or application from the OPIDIV?The public does not navigate to AddThis. AddThis works in the background.
Please describe how the public navigate to the third-party website or application:The public does not navigate to AddThis. The AddThis tools works when individuals are visiting HealthCare.gov. However, individuals are provided with a link that allows them to access the AddThis website from HealthCare.gov. The link, located on the screen requesting information for emailing purposes, is for the AddThis landing page and is not a government website nor a site owned or operated by CMS.  
If the public navigate to the third-party website or application via an external hyperlink, is there an alert to notify the public that they are being directed to a nongovernmental Website?No
Has the OPDIV Privacy Policy been updated to describe the use of a third-party Website or application?Yes
Provide a hyperlink to the OPDIV Privacy Policy:https://www.healthcare.gov/privacy/
Is an OPDIV Privacy Notice posted on the third-party Website or application?No
Is PII collected by the OPDIV from the third-party Website or application?No
Will the third-party Website or application make PII available to the OPDIV?No
Describe the PII that will be collected by the OPDIV from the third-party Website or application and/or the PII which the public could make available to the OPDIV through the use of the third-party Website or application and the intended or expected use of the PII:CMS does not collect any PII through the use of AddThis.
Describe the type of PII from the third-party Website or application that will be shared, with whom the PII will be shared, and the purpose of the information sharing:PII is not stored or shared.
If PII is shared, how are the risks of sharing PII mitigated?No PII is shared with CMS.
Will the PII from the third-party Website or application be maintained by the OPDIV?No
Describe how PII that is used or maintained will be secured:Not applicable
What other privacy risks exist and how will they be mitigated?

CMS' use of AddThis at HealthCare.gov aligns with federal and agency policy because the tool is used solely for the purposes of improving consumers’ services and activities online. To protect privacy and to be transparent about the use of AddThis, other privacy risks have been identified and mitigated:      

  • CMS recognizes that if AddThis is not implemented correctly in relation to HealthCare.gov, personal information could be collected about HealthCare.gov visitors. Therefore, to mitigate this risk, CMS only permits a limited number of trained and credentialed staff or contractors to implement AddThis.   
  • AddThis has a Federal Terms of Service (ToS) agreement that has been reviewed and complies with CMS's privacy notice.  
  • Information collected by AddThis is maintained by AddThis and not combined with any other information.    
  • AddThis' privacy policy which governs the use of its service can be found at AddThis' privacy policy page for individuals/consumers to read and review. Also, CMS conducts periodic reviews of the AddThis' privacy policy to identify any changes that may affect CMS’ use. If changes are identified, updates will be made by CMS to align with agency objectives and privacy policies so that changes do not present unreasonable or unmitigated risks to consumer privacy.  
  • Individuals have the choice to not use the AddThis service. This choice can be made by not clicking on the icon and/or sharing information on HealthCare.gov.
  • If you choose to navigate to the AddThis website from HealthCare.gov link, you are subject to the CMS linking policy;   
  • HealthCare.gov links to other HHS sites, other government sites, and occasionally to private organizations. Once you leave HealthCare.gov, you are subject to the privacy policy for the sites you are visiting. HHS is not responsible for the contents of any off-site web page. A link to a page does not constitute an endorsement.

 

 

Third-Party Web and Application (TPWA) Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services