QualityNet Metrics Analytics for CMS
Date signed: 7/24/2026
| PIA Questions | PIA Answers |
|---|---|
| OPDIV: | CMS |
| PIA Unique Identifier: | P-7647556-776754 |
| Name: | QualityNet Metrics Analytics for CMS |
| The subject of this PIA is which of the following? | Major Application |
| Identify the Enterprise Performance Lifecycle Phase of the system. | Operate |
| Is this a FISMA-Reportable system? | Yes |
| Does the system include a Website or online application available to and for the use of the general public? | Yes |
| Identify the operator: | Agency |
| Is this a new or existing system? | New |
| Does the system have Security Authorization (SA)? | Yes |
| Date of Security Authorization | 8/11/2025 |
| Describe the purpose of the system | QualityNet Metrics Analytics for CMS (QMAC) consists of 2 Internet-facing web solutions that leverages machine learning and natural language processing to analyze data from two unique data sources, public comments on new CMS regulations and nursing home survey data. During the Public comment phase of the process, CMS accepts public comments through the Regulations.gov website. QMAC receives comment data from Regulations.gov and automates the comment review process with machine learning and natural language processing. Additionally, the machine learning models developed to support public comments analysis, machine learning models are in place to support the analysis of the Nursing Home Survey data collected in the Statement of Deficiencies (SOD2567) form. The QMAC Machine Learning (ML) models and Natural Language Processing (NLP) techniques are leveraged to categorize stakeholder feedback (collected in multiple venues), thereby enabling CMS analysts to use the system to quickly identify comments that may impact program/policy decisions. The system also utilizes Artificial Intelligence (AI) to minimize bias through topic, theme, stakeholders, and sentiment models that standardize the analysis process, and provide insights that were previously difficult to obtain manually. The use of AI and training of models will not contain any Personal Health Information (PHI) or Personally Identifiable Information (PII). The Privacy Impact Assessment (PIA) will be updated to reflect any future AI use cases that introduce new privacy risks. All AI tools and technologies are part of AWS FedRAMP capabilities. They are not Op/Div or federally developed. |
| Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements) | QMAC collects and stores public comment data from Regulations.gov, and Nursing Home Survey data from Statement of Deficiencies (SOD2567) forms. Both data sources do not contain any PII. In addition to the comment data and survey data, QMAC stores end-user login IDs, name and email address of CMS employees and QMAC contractors as a log entry from a CMS authentication system, HARP (Health Care Quality Information Systems (HCQIS) Access Roles and Profile). QMAC provides their users the ability to share analyses and dashboards. These analyses and dashboards are stored and maintained by QMAC and do not contain any PII. |
| Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily. | QMAC stores public comment data from Regulations.gov and Nursing Home Survey data from Statement of Deficiencies (SOD2567) forms. Data is loaded into the QMAC application for processing and QMAC creates data insights concerning the public comments and Nursing Home Survey data. The data is displayed in a web-based application with reports and dashboards. Both data sources do not contain any PII. In addition to Regulations.gov and Nursing Home Survey data, end-user login IDs, name and email addresses of CMS employees and QMAC contractors are collected for monitoring website login activity to support ongoing security monitoring. |
| Does the system collect, maintain, use or share PII? | Yes |
| Indicate the type of PII that the system will collect or maintain. |
|
| Indicate the categories of individuals about whom PII is collected, maintained or shared. |
|
| How many individuals' PII in the system? | <100 |
| For what primary purpose is the PII used? | Email addresses, Names and User IDs are collected to monitor access to the website. Each time a user logsin to the websites, their Email Address, name, and User ID are stored in a log file for security monitoring purposes. |
| Describe the secondary uses for which the PII will be used (e.g. testing, training or research) | None, there are no secondary uses. |
| Describe the function of the SSN. | Not Applicable, SSN is not collected, stored, maintained, shared, or used in the system. |
| Cite the legal authority to use the SSN. | Not Applicable |
| Identify legal authorities governing information use and disclosure specific to the system and program. | The statutory mission of the QIN-QIO Program is to improve the effectiveness, efficiency, economy, and quality of services delivered to Medicare beneficiaries. Social Security Act, Titles 18 and 19, particularly Sections 1819, 1864, 1865, 1867, 1891, 1899, 1902, and 1919 |
| Are records on the system retrieved by one or more PII data elements? | No |
| Identify the sources of PII in the system: Directly from an individual about whom the information pertains |
|
| Identify the sources of PII in the system: Government Sources | |
| Identify the sources of PII in the system: Non-Government Sources | |
| Identify the OMB information collection approval number and expiration date | Not Applicable, the QMAC system is not the collector of data. OMB information collection and the responsibility for this would the HARP system. |
| Is the PII shared with other organizations? | No |
| Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason. | QMAC: Not applicable, the notice is the responsibility of the HARP system. The HARP system provides the user-id, name and email address to QMAC to be able to validate the user and allow access to the system. |
| Is the submission of the PII by individuals voluntary or mandatory? | Voluntary |
| Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason. | Not applicable, opt-out is the responsibility of the HARP system. HARP provides the user-id, name and email address to QMAC to be able to validate the user and allow access to the system. |
| Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changes since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained. | No major changes are planned or anticipated. In the event such a change is made, an e-mail to the user community would be sent to inform users of the change. |
| Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not. | Users can contact the CCSQ Service Center to submit questions, concerns, or comments. |
| Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not. | Administrators review log records during security events and at a minimum once a week if no suspicious activity is noted. |
| Identify who will have access to the PII in the system and the reason why they require access. |
|
| Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII. | All administrators that access log data containing the PII have been approved by the CMS. The approval is captured in a ticketing tool, ServiceNow through a request ticket. A request ticket must be submitted via the ServiceNow and must receive approval before the user is granted access. |
| Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job. | Administrators are only provided access to PII that is needed for their security duties of monitoring system access to ensure access is valid and not malicious in nature. |
| Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained. | All system and site administrator users are required to take an online Security Awareness Training and Identifying and Safeguarding Personally Identifiable Information Computer based training before they are granted user credentials. This training is required to be renewed annually for all existing users. All users are trained to perform the duties necessary to work within the system to perform their specific job functions. Personnel with Security Significant Responsibility (SSR) such as developers, infrastructure/system administrators, database administrators, architects, security engineers, etc. also complete CMS Agency Role-Based Training (RBT) requirements on an annual basis, corresponding to the user’s National Institute of Standards and Technology (NIST) National Initiative for Cybersecurity Education NICE role. Any new Application Development Organizational (ADO) users or existing ADO users with a new role complete RBST requirement within 60 days of beginning their new role. |
| Describe training system users receive (above and beyond general security and privacy awareness training) | Personnel with Security Significant Responsibility (SSR) such as developers, infrastructure/system administrators, database administrators, architects, security engineers, etc. also complete CMS Agency Role-Based Training (RBT) requirements on an annual basis, corresponding to the user’s NIST National Initiative for Cybersecurity Education NICE role. Any new Application Development Organizational (ADO) users or existing ADO users with a new role complete RBST requirement within 60-days of beginning their new role. |
| Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices? | Yes |
| Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules. | The QualityNet Media Protection and Decommission Procedures provides the guidance on how to protect media through proper access controls, media marking, media transportation, proper media sanitization techniques, and controls for sanitization and disposal decisions considering the security categorization of the associated system’s confidentiality. Data is stored and destroyed following the CMS Records schedule which follows NARA General Record Schedules (GRS). Per Disposition Authority: N1-440-09-3, Temporary. Cutoff annually. Delete/destroy when 10-years old, or when no longer needed for Agency business, whichever is later. |
| Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls. | PII is secured with a variety of security controls as required by FISMA and the CMS Security Program. Operational controls include but are not limited to: contingency plans and annual testing, backups of all files, off site storage of backup files, physical security including secure buildings with access cards for entry, secure data center requiring additional access permissions for entry, security guards, background checks for all personnel, incident response procedures for timely response to security and privacy incidents, initial security training with refresher courses annually, and annual role based security training for personnel with assigned security roles and responsibilities. Technical controls include but are not limited to user authentication with least privilege authorization, fire walls, Intrusion Detection and Prevention systems (IDS/IPS), hardware configured with NIST security checklists, encrypted communications, hardware configured with a deny all/except approach, auditing, and correlation of audit logs from all systems. Management controls include but are not limited to, Certification and Accreditation (C&A), annual security assessments, monthly management of outstanding corrective action plans, ongoing risk assessments, and automated continuous monitoring. |
| Identify the publicly-available URL: | Citation Analysis and Summary Assistant Feedback Analysis System - Test |
| Does the website have a posted privacy notice? | No |
| Is the privacy policy available in a machine-readable format? | No |
| Does the website use web measurement and customization technology? | Yes |
| Select the type of website measurement and customization technologies is in use and if is used to collect PII. (Select all that apply) |
|
| Does the website have any information or pages directed at children under the age of thirteen? | No |
| Does the website contain links to non-federal government website external to HHS? | No |
Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services