Skip to main content

Continuously Available CMS Hosting Environment

Date signed: 8/26/2026

PIA information for the Continuously Available CMS Hosting Environment system
PIA QuestionsPIA Answers
OPDIV:CMS
PIA Unique Identifier:P-3162708-614316
Name:Continuously Available CMS Hosting Environment
The subject of this PIA is which of the following?General Support System
Identify the Enterprise Performance Lifecycle Phase of the system.Operate
Is this a FISMA-Reportable system?Yes
Does the system include a Website or online application available to and for the use of the general public?No
Identify the operator:Contractor
Is this a new or existing system?Existing
Does the system have Security Authorization (SA)?Yes
Date of Security Authorization9/28/2023
Indicate the following reason(s) for updating this PIA. Choose from the following options.
  • PIA Validation (PIA Refresh/Annual Review)
Describe in further detail any changes to the system that have occurred since the last PIA.

Software Deployments: 

  1. IBM Products: IBM Z Automation, IBM CL Supersession, IBM DevOps Deploy, replaced CA Broadcom software.
  2. Entuity, a replacement for the SolarWinds software.
  3. Device42 software collects system hardware and virtual machine (VM) information. 
  4. PDS software simplifies dealing with the contents of Partitioned Data Sets (PDS). 
  5. Apache Maven- DevOps automation.


Hardware Deployments: 

  1. Replaced Cisco switches with Arista switches in Central office), Local offices and regional office CMS offices
  2. Cohesity data protection replaced Actifio solution.
    Cisco Firepower Cluster was also deployed, and it is a high-availability Next Generation Firewall (NGFW) deployment (e.g., Firepower 42xx series) positioned at the data center edge.


Expansion of DRaaS-CACHE ATO Boundary

  1. Systems pulled under ATO boundary: Central and Remote location equipment, Baltimore Data Center (BDC) legacy infrastructure/shared systems and Companion Data Services (CDS) Virtual Data Center (VDC) legacy management systems (CDS VDC retired as of 8-10-26), "CMS Digital Multimedia Services (DMS high-capacity multimedia storage systems and Oracle Cloud@Customer infrastructure located in Ashburn, VA and Phoenix, AZ.
  2. In addition, a new data center site managed by Iron Mountain located in Phoenix, AZ. 

Change in Internet Service: CMS moved from Trusted Internet Connection (TIC) 1 technology to TIC 3 technology which called for a high-availability cluster of Zscaler (ZIA) Private Service Edges (PSE). 

Describe the purpose of the systemThe Disaster Recovery as a Service-Continuously Available CMS Hosting Environment (DRaaS-CACHE) is a FIPS-199 designated HIGH system providing a dedicated physical space to be used for disaster recovery purposes and General Support System (GSS). DRaaS-CACHE provides CMS agency wide, on-demand Disaster Recovery (DR) and Data Management( DMManagement (DM) services during periods of disruption for primary hosting facilities. The DRaaS-CACHE environment has all the necessary hardware, commercial-off-the-shelf software, tools, materials, documentation, parts, equipment, transportation, and supplies necessary to support CMS enterprise DR and DM services.  In addition, DRaaS-CACHE provides operational and security services to the data center tenants. There are three geographically disperse locations for the DRaaS-CACHE data centers: Ashburn, VA, Phoenix, AZ and Kent, WA.  The boundary also includes the CMS central office and remote offices. 
Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements)

Employee and contractor credentials to include first name, last name, work physical street address, work phone number, work email address, User ID, user's hashed password are collected. The PII (user first and last name, cell phone number and email address) is collected and maintained to grant user’s access to the system. This information is collected to associate the username and password with an individual. The username and password are created and distributed by the system administrator to the individual user.

This PII is retained only if the individual has authorized access to the DRaaS-CACHE environment and/or systems. Once a user's access is no longer authorized, it is removed from the environment.

Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily.

Continuously Available CMS Hosting Environment (DRaaS-CACHE) is the physical data center space, infrastructure components and enterprise services available for CMS systems and applications hosted in the DRaaS-CACHE General Support System.  There are three geographically disperse locations of DRaaS-CACHE, Ashburn, VA, Phoenix, AZ and Kent, WA. These three locations act as disaster recovery sites for the others.

DRaaS-CACHE does not directly collect, maintain, or disseminate information, but rather provides support infrastructure for other CMS applications to perform these functions. 

The description of PII collected for employees and contractors includes first name, last name, work physical street address, work phone number, work email address, User ID, user's hashed password. The PII (user first and last name, cell phone number and email address) is collected and maintained to grant user’s access to the system.

This PII is obtained through Lightweight Directory Access Protocol (LDAP) which is linked with Enterprise User Administration (EUA). The attributes are obtained from the EUA system.

The PII collected is necessary to manage authorized user credentials for access to the DRaaS-CACHE environment and these credentials are not shared with any other systems.
The first name, last name, work physical street address, work phone number, work email address, are obtained from the EUA system to identify/link a person with each User ID created to access the DRaaS-CACHE environment.  This data is also used to contact each user in relation to their access to provide user ids and passwords. 

Does the system collect, maintain, use or share PII?Yes
Indicate the type of PII that the system will collect or maintain.
  • Name
  • E-Mail Address
  • Phone Numbers
  • Other - Work physical street address, and user credentials - User ID and Password. The DRaaS-CACHE LDAP system is linked with EUA which is where the LDAP system retrieves the user attributes. The EUA system manages the PII attributes.
Indicate the categories of individuals about whom PII is collected, maintained or shared.
  • Employees
  • Vendors/Suppliers/Contractors
How many individuals' PII in the system?500-4,999
For what primary purpose is the PII used?The primary purpose of Personally Identifiable Information (PII), user credentials, is for system access.
Describe the secondary uses for which the PII will be used (e.g. testing, training or research)N/A
Describe the function of the SSN.DRaaS-CACHE does not use or collect SSN's.
Cite the legal authority to use the SSN.N/A - No SSNs are collected
Identify legal authorities​ governing information use and disclosure specific to the system and program.5 U.S.C 301, Departmental Regulations
Are records on the system retrieved by one or more PII data elements?No
Identify the sources of PII in the system: Directly from an individual about whom the information pertains
  • In-person
  • Online
Identify the sources of PII in the system: Government Sources
  • Within the OPDIV
Identify the sources of PII in the system: Non-Government Sources
  • Other - Individual access request from CMS, CMS contractors and CMS subcontractors
Identify the OMB information collection approval number and expiration dateN/A
Is the PII shared with other organizations?No
Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason.Not Applicable. Providing any notification is the responsibility of the EUA system.
Is the submission of the PII by individuals voluntary or mandatory?Voluntary
Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason.The PII that is collected is necessary to perform their job function. Therefore, there isn’t a method for an individual to opt-out.
Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changes since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained.Notification is not provided to users because the PII is not directly collected from the individual. The PII that is collected is used for user account creation and all users must sign an account request form prior to account creation.
Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not.The PII data is obtained from another CMS system, therefore, there is no process in place by DRaaS-CACHE to address an individuals' concerns. However, complaints regarding the use of a system user PII can be sent to any of DRaaS-CACHE system administrators. These complaints will be given a corresponding ticket to ensure that the system administrators practice due diligence to review the issue, question, or concerns of the individual. Data collection practices, privacy and security safeguards are of the utmost importance to the AWS system management and any concerns raised will be reviewed.
Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not.

To maintain the integrity, availability, accuracy, and relevancy of the PII, System Administrators review user accounts annually. Any anomalies are addressed and resolved by contacting the user, and modifying their user data, or by removing their access if no longer required. Under this process, outdated, unnecessary, irrelevant, and inaccurate PII is identified and deleted. The PII is available as needed and is sufficient (minimum required) for the purposes needed. Only system administrators can create or modify PII.

Activities of all users including system administrators are logged and reviewed by System Information System Security Officer (ISSO) to identify abnormal activities if any.

Identify who will have access to the PII in the system and the reason why they require access.
  • Administrators: Administrators require access to PII to maintain the system.
Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII.Individual requesting access to DRaaS-CACHE must first go through the EUA onboarding process. After completing the EUA onboarding process, the user will be given a EUA ID with the appropriate job code, which determines the user role in the DRaaS-CACHE environment. The user's manager will open a JIRA (a digital issue tracking tool) ticket requesting the subrole controlled by the DRaaS-CACHE Enterprise Lightweight Directory Access Protocol (LDAP) system. The JIRA ticket must contain justification for the access must be approved by the System Security Officer. The access granted is the minimal access required to perform one's job functions to include access to PII. 
Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job.The methods in place to allow only minimum access to PII are approval and monitoring of system access requests and role-based access controls, so that users are restricted to only the resources needed to perform their job functions.
Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained.CMS employees and direct contractors are required to take annual training regarding the security and privacy requirements for protecting PII. In additional, role-based training is provided to individuals with significate access or security responsibilities. This annual role-based training is required by the CMS Chief Information Officer Directive 12-03. All training is modeled on and is consistent with training offered by the Department of Health and Human Services and CMS.
Describe training system users receive (above and beyond general security and privacy awareness training)None
Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices?Yes
Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules.DRaaS-CACHE follows the CMS records schedules, per the National Archive and Records Administration (NARA). The NARA General Records Schedule (GRS) 3.1 states that technology records will be destroyed after a maximum of five years. The NARA GRS 3.2 states that information security records will be destroyed after a maximum of six years.
Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls.

Physical: DRaaS-CACHE is located at a secured facility. Physical controls are in place such as security guards to ensure access to the buildings is granted to only authorize individuals. Identification of personnel is checked at the facility. 

Administrative: The principle of least privilege is used as well as a role-based access control to ensure system administrators are granted access on a "need-to-know" and "need-to-access” commensurate with their assigned duties. The information is protected using Access Control Lists (ACLs) defined for allowing only administrator access to the PII.

Technical: This access is further protected by the system controls which enforce two-factor authentication into the Amazon Web Service (AWS) system. Furthermore, the information is maintained in an encrypted manner by ensuring the databases are encrypted. Access is provided based on an approved request by the Information System Security Officer (ISSO). Lastly, audit logs are reviewed for suspicious activity by the ISSO on a regular basis.

Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services