Research Accessible Products Innovation and Deployable Solutions
Date signed: 8/26/2026
| PIA Questions | PIA Answers |
|---|---|
| OPDIV: | CMS |
| PIA Unique Identifier: | P-6205162-683713 |
| Name: | Research Accessible Products Innovation and Deployable Solutions |
| The subject of this PIA is which of the following? | Major Application |
| Identify the Enterprise Performance Lifecycle Phase of the system. | Operate |
| Is this a FISMA-Reportable system? | Yes |
| Does the system include a Website or online application available to and for the use of the general public? | No |
| Identify the operator: | Contractor |
| Is this a new or existing system? | Existing |
| Does the system have Security Authorization (SA)? | Yes |
| Date of Security Authorization | 7/17/2026 |
| Indicate the following reason(s) for updating this PIA. Choose from the following options. |
|
| Describe in further detail any changes to the system that have occurred since the last PIA. | Research Accessible Products Innovation and Deployable Solutions (RAPIDS) has undergone the following changes that warrant an updated privacy review. The system continues to operate within the same CMS authorized AWS environment; however, the underlying architecture has been updated from a Python-based batch processing and analytics platform to a serverless model leveraging additional AWS tools to support document accessibility analysis and workflow automation. External-facing API endpoints are also being introduced to support expanded integration capabilities. To date, no new categories of data have been ingested because of these changes. This PIA is being updated proactively to account for a potential future use case involving integration with the CMS Section 508 mailbox, which could introduce unstructured content that may include Personally Identifiable Information (PII) or Protected Health Information (PHI). As a precautionary measure and in support of the system's ATO renewal at the moderate impact level, this assessment has been updated to evaluate the privacy implications of that potential data pathway should it be implemented. |
| Describe the purpose of the system | The purpose of RAPIDS is to explore and conduct pilots focused on improving and expanding Section 508 accessibility innovations within CMS. The environment serves as a dedicated platform to research, test, and prototype accessibility-focused tools and capabilities that can be adopted more broadly across the agency. This includes the exploration of assistive technologies such as screen readers and text-to-speech software, as well as inclusive design practices that make digital products and services more usable for people with disabilities. To further advance accessibility outcomes this will also include piloting AI-assisted document remediation workflows, such as automated generation of alternative text for images, metadata tagging, and document structure analysis, as well as exploring agent-based automation to improve the efficiency of accessibility review processes. The Privacy Impact Assessment (PIA) will be updated to reflect any future AI use cases that introduce new privacy risks. |
| Describe the type of information the system will collect, maintain (store), or share. (Subsequent questions will identify if this information is PII and ask about the specific data elements) | RAPIDS (Research Accessible Products Innovation and Deployable Solutions) is an internally operated CMS system designed to support Section 508 accessibility testing and document remediation workflows. The system is not designed to solicit, collect, or maintain personal information directly from members of the public or from external users. All interactions with the system are conducted by authorized CMS staff and contractors operating within the CMS organizational boundary, who submit documents through a secure Representational State Transfer Application Programming Interface (REST API) for the purpose of automated accessibility analysis. The primary category of information processed by RAPIDS consists of documents submitted internally by CMS personnel for Section 508 compliance testing and remediation. These documents may include file formats such as PDFs, Word documents, and PowerPoint presentations that are uploaded by authorized users for the purpose of evaluating and improving digital accessibility. The content of these documents is determined entirely by submitting CMS users or program office and is not controlled or prescribed by the RAPIDS system itself. To date, no Personally Identifiable Information (PII) or Protected Health Information (PHI) has been ingested by the system because of its current operations. It is important to note that currently all documents are manually added to the system and reviewed prior to submission to ensure they do not contain PII or PHI. However, this PIA is being updated proactively to account for a potential future integration with the CMS Section 508 mailbox, which could introduce unstructured document content that may incidentally contain PII elements including Social Security Numbers, names, dates of birth, email addresses, mailing addresses, phone numbers, and race or sex information, as well as PHI; should this integration be implemented, appropriate privacy controls and an updated privacy review will be completed prior to activation. |
| Provide an overview of the system and describe the information it will collect, maintain (store), or share, either permanently or temporarily. | RAPIDS (Research Accessible Products Innovation and Deployable Solutions) is an internally operated CMS platform developed and maintained by the Application Development Organization (ADO) IT Data Solutions (ITDS) within the CMS Office of Information Technology (OIT). The system serves as a dedicated research and piloting environment for Section 508 accessibility innovations, with a mission to explore, test, and prototype accessibility-focused tools and capabilities that can be adopted more broadly across the agency. RAPIDS supports AI-assisted document remediation workflows, including automated generation of alternative text for images, metadata tagging, and document structure analysis as well as automation to improve the efficiency of accessibility review processes. The system operates entirely within the CMS-authorized Amazon Web Services (AWS) East Enclave and is not accessible to or designed for use by members of the public. In addition to the submitted documents, the system generates and maintains AI-produced accessibility analysis outputs and test results. These outputs are the product of automated accessibility testing workflows and AI-driven document remediation processes executed within the system boundary using Amazon Bedrock and AWS Lambda. These results are made available to authorized CMS 508 Team members through the API for use in improving the accessibility of CMS digital products and services. The system also maintains operational and audit data, including application logs, API activity records, and configuration and compliance data generated by AWS CloudTrail, Amazon CloudWatch, and AWS Security Hub. This operational data is retained solely for security monitoring, audit, and system integrity purposes. This Privacy Impact Assessment is being updated proactively to account for the different types of data that could be present in remediation documentation. The system could receive unstructured document content submitted through that mailbox channel, which may incidentally contain PII or PHI. This assessment does not reflect a current data collection practice but rather a forward-looking evaluation undertaken in support of the system's ATO renewal at the Moderate impact level. Any implementation of this integration will be subject to additional privacy review, appropriate data handling controls, and updates to this assessment prior to activation. |
| Does the system collect, maintain, use or share PII? | Yes |
| Indicate the type of PII that the system will collect or maintain. |
|
| Indicate the categories of individuals about whom PII is collected, maintained or shared. |
|
| How many individuals' PII in the system? | <100 |
| For what primary purpose is the PII used? | RAPIDS do not currently collect or use PII for any operational purpose. The system is an internally operated CMS platform in which authorized CMS staff and contractors submit documents for automated Section 508 accessibility testing and AI-driven document remediation. Any PII that may be present in the system exists only incidentally as unstructured content within documents submitted for accessibility analysis. It is not solicited, indexed, or used to retrieve records. It is important to note that all documents are currently manually added to the system and reviewed prior to submission to ensure they do not contain PII or PHI. However, this PIA is being updated proactively to acknowledge that unsolicited PII or PHI could be incidentally captured within submitted documents, and appropriate privacy controls will be evaluated and implemented should the volume or nature of document submissions change. |
| Describe the secondary uses for which the PII will be used (e.g. testing, training or research) | N/A |
| Describe the function of the SSN. | RAPIDS do not collect, use, or maintain Social Security Numbers (SSNs) as part of its current operations. The system is an internally operated CMS platform in which authorized CMS staff and contractors submit documents for automated Section 508 accessibility testing and AI-driven document remediation. No SSNs are solicited, indexed, or used to retrieve records within the system. In the event that a submitted document incidentally contains an SSN as unstructured content, the SSN would not be used by the system for any retrieval, authentication, or operational purpose. This PIA is being updated proactively to account for that potential future data pathway; however, no SSN collection or use is currently occurring. |
| Cite the legal authority to use the SSN. | As RAPIDS does not currently collect or use SSNs, no legal authority to use the SSN is applicable at this time. Should a future system change result in the intentional collection or use of SSNs, the system would be required to cite legal authority pursuant to Section 7 of the Privacy Act of 1974 (5 U.S.C. § 552a note), which requires federal agencies to inform individuals whether disclosure of their SSN is mandatory or voluntary, the statutory or other authority under which the SSN is solicited, and the uses that will be made of it. Any such future use would require an updated privacy review and, if applicable, the establishment or amendment of a System of Records Notice (SORN) prior to implementation. |
| Identify legal authorities governing information use and disclosure specific to the system and program. | The collection, maintenance, use, and disclosure of information within RAPIDS is governed by the following legal authorities: The Privacy Act of 1974 (5 U.S.C. § 552a) establishes the foundational framework for the federal government's collection, maintenance, use, and dissemination of personally identifiable information and applies to any records retrieved by a personal identifier. The E-Government Act of 2002 (44 U.S.C. § 3501 et seq.), including Section 208, requires federal agencies to conduct Privacy Impact Assessments for systems that collect, maintain, or disseminate PII, and serves as the direct legal basis for this assessment. The Federal Information Security Modernization Act of 2014 (FISMA, 44 U.S.C. § 3551 et seq.) governs the security and integrity of federal information systems, including the requirement for an Authority to Operate (ATO) at the appropriate impact level. The Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. § 794d), provides the programmatic legal authority for the RAPIDS mission, requiring federal agencies to develop, procure, maintain, and use accessible electronic and information technology. Additionally, CMS and HHS information governance policies, including the CMS Information Systems Security and Privacy Policy (IS2P2) and applicable HHS directives, govern the handling of information within CMS systems and provide the operational framework within which RAPIDS operates. |
| Are records on the system retrieved by one or more PII data elements? | No |
| Identify the sources of PII in the system: Directly from an individual about whom the information pertains | |
| Identify the sources of PII in the system: Government Sources |
|
| Identify the sources of PII in the system: Non-Government Sources | |
| Identify the OMB information collection approval number and expiration date | RAPIDS do not conduct a public information collection subject to the Paperwork Reduction Act (PRA) and therefore does not hold an OMB information collection approval number or associated expiration date. The system is an internally operated CMS platform used exclusively by authorized CMS staff and contractors for Section 508 accessibility testing and AI-driven document remediation. No information is solicited from members of the public, and no standardized forms or surveys are used to collect information from individuals outside of the federal government. Accordingly, PRA clearance is not applicable to this system at this time. |
| Is the PII shared with other organizations? | No |
| Describe the process in place to notify individuals that their personal information will be collected. If no prior notice is given, explain the reason. | RAPIDS do not directly solicit or collect personal information from individuals. The system is accessible only to authorized CMS staff and contractors who interact with it in their official capacity and are made aware of applicable federal information handling practices through standard CMS onboarding processes, Rules of Behavior acknowledgments, and system access agreements. Because no PII is intentionally collected from users and the system is not accessible to the public, individualized notice at the point of collection is not applicable under the current system design. Any PII that may be incidentally present within unstructured documents submitted for accessibility analysis is not solicited by the system and is not used for any operational purpose. |
| Is the submission of the PII by individuals voluntary or mandatory? | Voluntary |
| Describe the method for individuals to opt-out of the collection or use of their PII. If there is no option to object to the information collection, provide a reason. | RAPIDS do not currently provide an opt-out mechanism, as the system does not intentionally collect PII from any individual. Authorized CMS users and CMS 508 Team members who submit documents through the system do so voluntarily in their official capacity, and any PII that may be incidentally present in submitted unstructured documents is not solicited, indexed, or used for any operational purpose. Because the system is not public-facing and does not collect information directly from members of the public, a formal opt-out process is not applicable under the current system design. |
| Describe the process to notify and obtain consent from the individuals whose PII is in the system when major changes occur to the system (e.g., disclosure and/or data uses have changes since the notice at the time of original collection). Alternatively, describe why they cannot be notified or have their consent obtained. | As RAPIDS does not currently collect PII from individuals, there is no population of individuals from whom consent must be obtained or to whom change notifications must be directed under the current system design. In the event of a major system change that introduces intentional PII collection, CMS will update this Privacy Impact Assessment and publish the updated assessment in accordance with the requirements of the E-Government Act of 2002. Any new or materially changed data collection practices will be evaluated for the need to establish or amend a System of Records Notice (SORN) under the Privacy Act of 1974, which would provide public notice through the Federal Register prior to implementation. CMS will not implement any new PII collection pathway without completing the required privacy review and notification processes. |
| Describe the process in place to resolve an individual's concerns when they believe their PII has been inappropriately obtained, used, or disclosed, or that the PII is inaccurate. If no process exists, explain why not. | RAPIDS do not currently collect or maintain PII in a manner that would give rise to individual access or correction rights under the Privacy Act of 1974, as records are not retrieved by personal identifiers. In the event that an individual believes their PII has been inappropriately obtained, used, or disclosed in connection with the RAPIDS system, that individual may submit a concern or inquiry to the CMS Privacy Office through established CMS privacy complaint and redress processes. CMS is committed to addressing privacy concerns in accordance with the Privacy Act of 1974, applicable HHS and CMS privacy policies, and the CMS Information Systems Security and Privacy Policy (IS2P2). Should the system's design evolve to include intentional PII collection or retrieval by personal identifier, formal access and amendment procedures consistent with Privacy Act requirements will be established and documented in this assessment. |
| Describe the process in place for periodic reviews of PII contained in the system to ensure the data's integrity, availability, accuracy and relevancy. If no processes are in place, explain why not. | As RAPIDS does not currently collect or maintain PII as a defined data element, there is no standing population of PII records subject to periodic accuracy or relevancy review at this time. The system's operational and audit data including API activity logs, CloudTrail records, and CloudWatch application logs, is subject to ongoing monitoring and review through CMS Cloud security operations and the CMS continuous monitoring program. In the event that a future system change results in the intentional collection or maintenance of PII, CMS will establish appropriate data quality and records management procedures, including periodic reviews to assess the integrity, availability, accuracy, and relevancy of any PII maintained in the system, and will document those procedures in an updated version of this PIA prior to implementation. |
| Identify who will have access to the PII in the system and the reason why they require access. |
|
| Describe the procedures in place to determine which system users (administrators, developers, contractors, etc.) may access PII. | RAPIDS do not currently maintain PII as a defined data element. Access to the system is restricted exclusively to authorized CMS staff and contractors and is governed by CMS IS2P2 policies, enforced through API Key-based authentication provisioned by the system administrator on a need-to-know basis following the principle of least privilege. Access requests are reviewed and approved by the CMS ISSO and Business Owner prior to provisioning, and all authorized users are subject to CMS Rules of Behavior acknowledgments and background investigation requirements commensurate with the system's Moderate impact level. Because documents submitted for accessibility analysis may incidentally contain unstructured PII, access determinations are made with the understanding that authorized users may encounter such content in the course of their official duties. |
| Describe the methods in place to allow those with access to PII to only access the minimum amount of information necessary to perform their job. | RAPIDS enforces least privilege through a combination of technical and administrative controls. At the technical layer, API Key authentication is enforced at the AWS WAF and API Gateway, and AWS IAM roles and policies restrict access to underlying resources, including Amazon S3, DynamoDB, Lambda, and Bedrock, to only those with a documented operational need. At the administrative layer, the ISSO and system administrator conduct periodic access reviews to ensure access remains appropriate and that credentials for users who no longer require access are promptly revoked. |
| Identify training and awareness provided to personnel (system owners, managers, operators, contractors and/or program managers) using the system to make them aware of their responsibilities for protecting the information being collected and maintained. | CMS employees, managers and direct contractors, who access CMS systems, are required to take the annual Security and Privacy Awareness Training and recertify the training each year. At the end of the training course, a test is taken to verify the completion of the training. Contractors also complete their annual corporate security training. Individuals with privileged access must also complete role-based security training commensurate with the position they are working. |
| Describe training system users receive (above and beyond general security and privacy awareness training) | CMS employees and contractors with privileged access are required to complete role-based training and meet continuing education requirements commensurate with their role. Other training avenues such as conferences, seminars and classroom training provided by CMS/HHS are available apart from the regular annual training. |
| Do contracts include Federal Acquisition Regulation and other appropriate clauses ensuring adherence to privacy provisions and practices? | Yes |
| Describe the process and guidelines in place with regard to the retention and destruction of PII. Cite specific records retention schedules. | RAPIDS do not currently collect or maintain PII as a defined data element; however, documents submitted for accessibility analysis may incidentally contain unstructured PII. Operational and audit data, including CloudTrail logs, CloudWatch application logs, and Security Hub findings, is retained for a minimum of one year in active storage and three years in archive, consistent with NIST SP 800-53 AU-11 and CMS audit log retention policy, and governed by NARA GRS 3.2 (Information Systems Security Records). Documents submitted for accessibility analysis are retained in Amazon S3 only for the period necessary to complete the associated workflow. Secure deletion is enforced through CMS Cloud configuration controls consistent with NIST SP 800-88 media sanitization guidelines. |
| Describe, briefly but with specificity, how the PII will be secured in the system using administrative, technical, and physical controls. | Administrative: Access is governed by formal approval procedures overseen by the CMS ISSO and Business Owner. All users complete Rules of Behavior acknowledgments, are subject to appropriate background investigations, and complete required CMS security awareness training. The system undergoes continuous monitoring and periodic security assessments as part of the ATO process. Technical: All data in transit is protected via HTTPS, and all data at rest in Amazon S3 and DynamoDB is encrypted using AWS-managed keys enforced through AWS Config rules. Access is authenticated via API Key with AWS WAF providing additional protection at the API Gateway. System activity is continuously monitored through CloudWatch and CMS Cloud Splunk, with CloudTrail providing a complete audit trail and Security Hub providing CSPM. Physical: RAPIDS is hosted entirely within the CMS-authorized AWS East Enclave, a FedRAMP-authorized environment. Physical security of the underlying infrastructure is the responsibility of AWS under the shared responsibility model and is governed by AWS's FedRAMP authorization. CMS maintains no on-premises infrastructure associated with RAPIDS. |
Privacy Impact Assessment (PIA) published by CMS as an Operating Division of the U.S. Department of Health and Human Services