Pandemic Darlings The pandemic economy, in original documents
Home Source documents GAO-24-106638, COVID-19: HHS Needs to Identify Duplicative Pandemic IT Systems and Impl…

GAO-24-106638, COVID-19: HHS Needs to Identify Duplicative Pandemic IT Systems and Implement Key Privacy Requirements

Issuer
Government Accountability Office
Document type
Report

Summary

GAO-24-106638 is a September 2024 report by the Government Accountability Office to congressional committees on the Department of Health and Human Services' pandemic public health preparedness and response IT systems. The report states that GAO worked with HHS component agencies to identify 99 systems and that HHS did not attempt to identify duplication or overlap among them. It reports that 68 of the 99 systems collect and store personally identifiable information and that privacy impact assessments existed for 53 of the 68. GAO randomly selected nine systems to review privacy safeguards and makes 14 recommendations to HHS, including establishing a systems inventory. The letter, dated September 18, 2024, cites the Consolidated Appropriations Act, 2023 and the CARES Act as the basis for the review.

Summary drafted by a model from the document's text below and checked by script against that text before publication. It is a navigation aid, not a reading of what the document proves. Where AI is used

Full text

United States Government Accountability Office

Report to Congressional Committees

September 2024

COVID-19
HHS Needs to Identify
Duplicative Pandemic
IT Systems and
Implement Key
Privacy Requirements

GAO-24-106638


September 2024

COVID-19
HHS Needs to Identify Duplicative Pandemic IT
Systems and Implement Key Privacy Requirements
Highlights of GAO-24-106638, a report to
congressional committees

Why GAO Did This Study

What GAO Found

HHS and its component agencies are
responsible for managing data
collection activities to support public
health preparedness and response
during public health emergencies, such
as the COVID-19 pandemic. The
Consolidated Appropriations Act of
2023 reiterates the need for HHS to
improve these data collection
capabilities and includes provisions for
GAO to review those capabilities. In
addition, the CARES Act includes a
provision for GAO to monitor and
oversee the federal response to the
COVID-19 pandemic.

The Department of Health and Human Services (HHS) has not identified and
reduced unnecessary duplication of data in its systems supporting pandemic
public health preparedness and response. Because the department did not have
a comprehensive list of these systems, GAO worked with key HHS component
agencies and identified a total of 99 systems. HHS did not attempt to identify
duplication or overlap for these systems. However, in its high-level review of the
99 systems, GAO identified instances of duplicative pandemic public health
preparedness and response data in multiple systems. For example, two
pandemic systems that collected similar COVID-19 data, such as cases, deaths,
and hospitalization data are managed by the same program office.

This report addresses, among other
things, the extent to which HHS has
(1) identified and reduced unnecessary
duplication, overlap, or fragmentation
in its preparedness and response data
capabilities; and (2) instituted privacy
safeguards on selected systems when
collecting public health preparedness
and response data.
GAO identified lists of systems and
compared HHS and component
agency efforts to identify unnecessary
duplication, overlap, and fragmentation
to federal law and guidance. GAO also
randomly selected nine systems for
review of component agency
implementation of privacy safeguards
for systems that collect and store PII.

Regarding privacy, according to the component agencies, 68 of the 99 identified
systems collect and store personally identifiable information (PII). These
agencies developed privacy impact assessments (PIA) for 53 of the 68; 15 did
not have such assessments. Such assessments are essential to identifying and
mitigating the privacy risks of systems containing PII. Until HHS ensures that
PIAs are developed for all of its systems containing PII, it will have less
assurance that privacy risks are assessed to prevent unauthorized disclosure.
Further, HHS and its component agencies did not implement all of the key
privacy safeguards for the nine systems that GAO randomly selected for review
(see figure). As a result, information collected and stored by some of these
systems may be at higher risk for unauthorized disclosure.
HHS Component Agencies Implementation of Key Privacy Safeguards for Selected Pandemic
Systems

What GAO Recommends
GAO is making 14 recommendations
to HHS, including establishing a
systems inventory, addressing
duplicative data, and fully
implementing privacy safeguards.
HHS generally agreed with the
recommendations, although stating
that two may not be feasible. GAO
continues to believe they are valid.

View GAO-24-106638. For more information,
contact Jennifer R. Franks at (404) 679-1831
or franksj@gao.gov.
United States Government Accountability Office


Contents

Letter

1
Background
HHS Has Not Identified and Reduced Unnecessary Duplication,
Overlap, or Fragmentation of Data in Its Pandemic Systems
HHS Had Not Proactively Identified Funding and Staffing
Resources for Its Pandemic Systems
HHS Partially Implemented Key Privacy Safeguards for Collecting
PII in Systems Supporting Pandemic Response
Conclusions
Recommendations for Executive Action
Agency Comments and Our Evaluation

24
38
39
41

Appendix I

Objectives, Scope, and Methodology

44

Appendix II

HHS Component Agencies Use Various Systems to Prepare for and
Respond to Pandemic Public Health Emergencies

50

HHS Component Agency Comments on the Impact of Pandemic
Funding

67

Appendix IV

Comments from the Department of Health and Human Services

69

Appendix V

GAO Contact and Staff Acknowledgments

71

Table 1: Department of Health and Human Services (HHS)
Pandemic Public Health Preparedness and Response
Systems with the Greatest Reported Costs in Fiscal Year
2023
Table 2: Department of Health and Human Services (HHS)
Pandemic Public Health Preparedness and Response
Systems

21

Appendix III

5
11
18

Tables

Page i

50

GAO-24-106638 HHS Public Health Data Capabilities


Figures
Figure 1: Department of Health and Human Services (HHS)
Component Agencies that Support Public Health
Preparedness and Response and Their Key Missions
Figure 2: GAO Definitions of Duplication, Overlap, and
Fragmentation
Figure 3: Examples of Funding Sources for the Department of
Health and Human Services (HHS) Pandemic Public
Health Preparedness and Response Systems
Figure 4: Steps for Implementing the Risk Management
Framework
Figure 5: The Extent to Which HHS Component Agencies
Implemented Key Privacy Requirements for Selected
Systems
Figure 6: The Extent to Which HHS Component Agencies
Implemented System of Record Notices for Selected
Systems
Figure 7: The Extent to Which HHS Component Agencies
Developed Security Categorizations for the Selected
Systems
Figure 8: The Extent to Which HHS Component Agencies
Developed Privacy Plans for the Selected Systems
Figure 9: The Extent to Which HHS Component Agencies
Assessed Privacy Controls for the Selected Systems
Figure 10: The Extent to Which HHS Component Agencies
Developed Authorizations to Operate for the Selected
Systems
Figure 11: The Extent to Which HHS Component Agencies
Conducted Monitoring for Privacy Controls for the
Selected Systems

Page ii

6
9
19
28
30
31
33
35
36
37
38

GAO-24-106638 HHS Public Health Data Capabilities


Abbreviations
ASPR
ATO
DCIPHER
CBER
CDC
CIO
CIS
COVID-NET
CRRSA
DMI
FDA
FITARA
FTE
HHS
HIV
HRSA
IHS
IT
NIH
NIST
OES
OMB
O&M
PDUFA
PIA
PII
SAOP
SORN

Administration for Strategic Preparedness and Response
authorization to operate
Data Collation and Integration for Public Health Event
Response
Center for Biologics Evaluation and Research
Centers for Disease Control and Prevention
Chief information officer
case isolate surveillance
COVID-19 Associated Hospitalization Surveillance
Network
Coronavirus Response and Relief Supplemental
Appropriations Act
data modernization initiative
Food and Drug Administration
Federal Information Technology Acquisition Reform Act
full-time equivalent
Department of Health and Human Services
Human Immunodeficiency Virus
Health Resources and Services Administration
Indian Health Service
information technology
National Institutes of Health
National Institute of Standards and Technology
outbreak event surveillance
Office of Management and Budget
operations and maintenance
Prescription Drug User Fee Act
privacy impact assessment
personally identifiable information
senior agency official for privacy
system of records notice

This is a work of the U.S. government and is not subject to copyright protection in the
United States. The published product may be reproduced and distributed in its entirety
without further permission from GAO. However, because this work may contain
copyrighted images or other material, permission from the copyright holder may be
necessary if you wish to reproduce this material separately.

Page iii

GAO-24-106638 HHS Public Health Data Capabilities


Letter

441 G St. N.W.
Washington, DC 20548

September 18, 2024
The Honorable Bernard Sanders
Chair
The Honorable Bill Cassidy, M.D.
Ranking Member
Committee on Health, Education, Labor and Pensions
United States Senate
The Honorable Cathy McMorris Rodgers
Chair
The Honorable Frank Pallone, Jr.
Ranking Member
Committee on Energy and Commerce
House of Representatives
Public health emergencies, such as the COVID-19 pandemic, can
weaken our economy, threaten national security, cause hundreds of
thousands of casualties, and damage public morale and confidence.
COVID-19 drew attention to the urgent need for public health officials to
access real-time information about emerging threats to enable them to
make timely, responsive decisions.
Public health officials rely on information from a number of key sources to
provide the situational awareness they need to prepare for and respond
to a variety of public health emergencies, such as pandemics. This
information includes critical response resources, medical care capacity,
environmental threats, and the preparedness status of the many public
health jurisdictions across the country. The Department of Health and
Human Services (HHS) and its component agencies have developed and
implemented systems to collect and analyze this information for public
health preparedness and response during pandemics. 1
The Consolidated Appropriations Act, 2023 highlights the need for HHS to
improve its data capabilities for public health preparedness and response

1HHS operating divisions include Centers for Disease Control and Prevention, the

Administration for Strategic Preparedness and Response, Food and Drug Administration,
Indian Health Service, National Institutes of Health, and Health Resources and Services
Administration, among others. For the purpose of this report, they are hereinafter
collectively referred to as component agencies.

Page 1

GAO-24-106638 HHS Public Health Data Capabilities


during pandemics. 2 The act includes provisions for us to report on HHS
and its component agencies’ efforts to identify and reduce duplication,
overlap, or fragmentation for pandemic public health preparedness and
response data capabilities, and to protect personally identifiable
information (PII). 3
In addition, the CARES Act includes a provision for us to report regularly
on the federal response to the pandemic. Specifically, the act calls for us
to conduct monitoring and oversight of the federal government’s efforts to
prepare for, respond to, and recover from the COVID-19 pandemic. 4
Our specific objectives for this review were to determine the extent to
which HHS has (1) identified and reduced unnecessary duplication,
overlap, or fragmentation in its pandemic public health preparedness and
response data capabilities; (2) identified funding and other resources for
the operation of its pandemic public health preparedness and response
data capabilities; and (3) instituted privacy safeguards when collecting
pandemic public health preparedness and response data.
For all three objectives, we focused on HHS and its component agencies
that maintain systems supporting pandemic public health preparedness
and response. These component agencies are the Administration for
Strategic Preparedness and Response (ASPR), Centers for Disease
Control and Prevention (CDC), Food and Drug Administration (FDA),
Health Resources and Services Administration (HRSA), Indian Health
Service (IHS), and National Institutes of Health (NIH).
To address the first objective, we identified requirements in the
Consolidated Appropriations Act, 2023 aimed at identifying and reducing
duplication, overlap, or fragmentation in pandemic public health
2Consolidated Appropriations Act, 2023, Pub. L. No. 117-328, § 2216, 136 Stat. 5740

(2022). The data capabilities include the collection of public health preparedness,
response, and recovery data regarding disease tracking, hospitalizations, critical care
capacity, and testing programs for diseases, such as COVID-19. For the purposes of this
report, the systems we discuss are those that assist HHS in pandemic preparedness and
response, however, these systems could also have other functions related to public
health.
3Personally identifiable information is any information that can be used to distinguish or

trace an individual’s identity, such as name, date or place of birth, and Social Security
number; or that otherwise can be linked to an individual.

4Pub. L. No. 116-136, § 19010(c), 134 Stat. 579 (2020). We regularly issue government-

wide reports on the federal response to COVID-19. These reports are available on GAO’s
website at https://www.gao.gov/coronavirus.

Page 2

GAO-24-106638 HHS Public Health Data Capabilities


preparedness and response data capabilities. We asked HHS and its
component agencies to provide a list of systems that support pandemic
public health preparedness and response, and the data collected by each
system. We then compared the lists of systems provided by the
component agencies to systems identified as supporting pandemic public
health preparedness and response in previously issued GAO reports. 5
We analyzed the lists of systems to identify areas where programs may
request or collect the same data.
We also compared HHS and its component agencies’ efforts to identify
and reduce duplication, overlap, or fragmentation among its systems to
federal requirements. These requirements included the Consolidated
Appropriations Act, 2023 and the Federal Information Technology
Acquisition Reform Act (FITARA) of 2014. 6 We also compared HHS and
its component agencies’ efforts to identify, reduce, or better manage
duplication among their systems to key practices identified in a prior GAO
report. 7
We supplemented our analysis with interviews of relevant HHS officials in
ASPR, CDC, FDA, HRSA, IHS, and NIH. We discussed their efforts to
identify systems involving pandemic public health preparedness and
response data and their efforts to reduce unnecessary duplication when
collecting this data. In addition, we interviewed representatives from
selected national public health organizations representing state, territorial,
and local public health officials, including the Association of State and
Territorial Health Officials, Council of State and Territorial
Epidemiologists, and National Association of County and City Health
Officials. We discussed the actions the organizations have taken to
collaborate with the department regarding the use of systems that support
pandemic public health preparedness and response, and efforts to
identify duplicative systems.

5GAO, COVID-19: Pandemic Lessons Highlight Need for Public Health Situational

Awareness Network, GAO-22-104600 (Washington, D.C.: June 23, 2022) and Public
Health Information Technology, HHS Has Made Little Progress Toward Implementing
Enhanced Situational Awareness Network Capabilities, GAO-17-377 (Washington, D.C.:
Sep 6, 2017).

6Consolidated Appropriations Act, 2023, Pub. L. No. 117-328, 136 Stat. 5740 (2022). Carl

Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year
2015, Pub. L. No. 113-291, div. A, title VIII, subtitle D, 128 Stat. 3438 (2014).

7GAO, Fragmentation, Overlap, and Duplication: An Evaluation and Management Guide,
GAO-15-49SP (Washington, D.C.: Apr. 14, 2015).

Page 3

GAO-24-106638 HHS Public Health Data Capabilities


To address the second objective, we identified federal budgetary
requirements and best practices identified in a prior GAO report on
developing and managing program costs. 8 We then analyzed the HHS
component agencies’ lists for the reported fiscal year 2023 funding
sources and costs for the systems that support pandemic public health
preparedness and response activities. We also analyzed system funding
documentation, such as budget requests and contracts. We compared
the system funding information to the federal budgetary requirements and
best practices. In addition, we identified best practices in GAO’s IT
workforce planning framework. 9 We analyzed the HHS component
agencies’ lists for staffing information, including the number of full-time,
full-time equivalent, and part-time staff dedicated to the management of
the pandemic public health preparedness and response systems. 10 We
also analyzed system staffing documentation, such as staffing plans,
organization charts, and contracts. We then compared the staffing
information and documentation to the best practices for workforce
planning. Additionally, we supplemented our analysis with interviews with
relevant HHS officials in ASPR, CDC, FDA, HRSA, IHS, and NIH.
To address the third objective, we identified federal requirements aimed
at establishing safeguards for systems that store and process PII. 11 We
then compared HHS privacy policies, memorandums, and privacy impact
8The White House, National Security Memorandum on Countering Biological Threats,

Enhancing Pandemic Preparedness, and Achieving Global Health Security, NSM-15
(Washington, D.C.: Oct. 18, 2022); GAO, Cost Estimating and Assessment Guide: Best
Practices for Developing and Managing Program Costs, GAO-20-195G (Washington,
D.C.: Mar. 12, 2020).

9GAO, IT Workforce: Key Practices Help Ensure Strong Integrated Program Teams;

Selected Departments Need to Assess Skill Gaps, GAO-17-8 (Washington, D.C.: Nov. 30,
2016).

10A full-time equivalent is a standard measure of labor that reflects the total number of
regular straight-time hours (i.e., not including overtime or holiday hours) worked by
employees divided by the number of compensable hours applicable to each fiscal year.
See the Office of Management and Budget Circular No. A-11, Preparation, Submission,
and Execution of the Budget (Washington, D.C.: Aug. 11, 2023).
11E-Government Act of 2002, Pub. L. No. 107-347, § 208, 116 Stat. 2899, 2921 (Dec. 17,

2002) (44 U.S.C. § 3501 note); Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896
(Dec. 31, 1974) (codified as amended at 5 U.S.C. § 552a); Office of Management and
Budget, Managing Information as a Strategic Resource, Circular A-130 (Washington,
D.C.: July 28, 2016); OMB Guidance for Implementing the Privacy Provisions of the EGovernment Act of 2002, M-03-22 (Washington, D.C.: Sept. 26, 2003); and National
Institute of Standards and Technology SP 800-37, Revision 2: Risk Management
Framework for Information Systems and Organizations: A System Life Cycle Approach for
Security and Privacy (Gaithersburg, Md.: December 2018).

Page 4

GAO-24-106638 HHS Public Health Data Capabilities


assessments (PIAs) to the federal requirements. 12 We randomly selected
a sample of nine systems from the components’ lists of systems compiled
from objective one that store and process PII. 13 For the selected systems,
we then collected and analyzed security documentation, such as privacy
plans and controls, and compared the documentation to the federal
requirements. Additionally, we supplemented our analysis with interviews
with relevant HHS officials in ASPR, CDC, FDA, HRSA, IHS, and NIH. A
full description of our objectives, scope, and methodology can be found in
appendix I.
We conducted this performance audit from February 2023 to September
2024 in accordance with generally accepted government auditing
standards. Those standards require that we plan and perform the audit to
obtain sufficient, appropriate evidence to provide a reasonable basis for
our findings and conclusions based on our audit objectives. We believe
that the evidence obtained provides a reasonable basis for our findings
and conclusions based on our audit objectives.

Background

The mission of HHS is to enhance the health and well-being of Americans
by providing effective public health and human services. To support this
mission, HHS designates its component agencies with responsibilities for
managing public health preparedness and response activities during
public health emergencies, such as pandemics. Figure 1 describes the
key missions of the HHS component agencies related to public health
preparedness and response.

12A privacy impact assessment (PIA) analyzes agency information systems containing

personally identifiable information (PII) to ensure that the PII is handled according to
applicable privacy requirements. A PIA also determines the privacy risks associated with
an information system and evaluates ways to mitigate privacy risks.

13Our initial selection was of 10 systems and included FDA’s Event-based Text-mining for
Health Electronic Records system. FDA had initially included the system as one that
included PII. After our selection, FDA analyzed the information stored by the system and
determined that it did not include PII. Therefore, this system was removed from our final
evaluation of privacy requirements, resulting in nine systems. The findings from these
systems for each component, while randomly selected, are not generalizable to all
systems in that component. However, for the selected systems, we were able to assess
whether there were instances of the agencies not meeting all of the privacy requirements.

Page 5

GAO-24-106638 HHS Public Health Data Capabilities


Figure 1: Department of Health and Human Services (HHS) Component Agencies that Support Public Health Preparedness
and Response and Their Key Missions

Page 6

GAO-24-106638 HHS Public Health Data Capabilities


These component agencies collaborate with various entities to collect and
share important health information related to preparing for or responding
to pandemics. These entities include state, local, and territorial public
health agencies, health care providers, laboratories, and other federal
departments, such as the Department of Homeland Security.
HHS and its component agencies use a number of information systems to
carry out their mission. For example, ASPR used the Health Partner
Order Portal system to manage and report key data related to the
ordering and distribution of COVID-19 vaccines. Additionally, HHS
developed HHS Protect in April 2020 to help integrate COVID-19 data
and other types of health information collected by various federal, state,
and local public health and commercial entities. 14 Further, FDA used the
Adverse Event Reporting System to collect and maintain adverse event
reports submitted by health care professionals and consumers regarding
adverse events, such as side effects and injuries associated with drugs
and vaccines.

Federal Laws and
Guidance Advise Agencies
on Identification of
Duplication, Overlap, or
Fragmentation

In December 2014, Congress enacted FITARA, which requires agencies
to ensure that their chief information officers (CIO) have a significant role
in the decision process for budgeting, governance, and oversight
processes related to IT. 15 The law requires agency CIOs to conduct an
annual review of the agency’s portfolio of IT investments. During these
reviews, agency CIOs are to identify ways to increase the efficiency of IT
investments by identifying potential duplication and opportunities to
consolidate the management of IT services when making annual and
multi-year IT planning, programming, and budgeting decisions. Also,
agency CIOs are to identify potential cost savings from consolidating IT
investments and services.
We previously reported in 2018 that HHS had not developed IT
management policies that address the role of the agency CIO to improve
the management of the agency’s IT through portfolio reviews to identify
duplication. 16 We recommended that the Secretary of HHS ensure that
14According to CDC officials, HHS Protect management and ownership was later

transitioned to CDC.

15Carl Levin and Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal

Year 2015, Pub. L. No. 113-291, div. A, title VIII, subtitle D, 128 Stat. 3438 (2014).
16GAO, Federal Chief Information Officers: Critical Actions Needed to Address

Shortcomings and Challenges in Implementing Responsibilities, GAO-18-93 (Washington
D.C.: Aug 2, 2018).

Page 7

GAO-24-106638 HHS Public Health Data Capabilities


the department’s IT management policies address the role of the CIO for
key responsibilities, including conducting portfolio reviews. HHS agreed
with the recommendation. However, as of June 2024, HHS has yet to fully
implement it.
GAO’s Fragmentation, Overlap, and Duplication Guide also defines
guidance for agencies to identify, evaluate, and reduce, or better manage
instances of duplication, overlap, and fragmentation across their
programs and systems, and to avoid negative consequences, such as
wasting resources (e.g. time, money, and appropriate staff). 17 For the
purpose of this report, unnecessary duplication refers to an instance
where data capabilities are already being performed by another group in
a more efficient manner. Therefore, when an agency develops and
implements additional systems performing a similar task, this results in
redundancy. Figure 2 defines duplication, overlap, and fragmentation
across agency programs and systems.

17GAO-15-49SP.

Page 8

GAO-24-106638 HHS Public Health Data Capabilities


Figure 2: GAO Definitions of Duplication, Overlap, and Fragmentation

Consistent with the guide, steps for addressing duplication, overlap, and
fragmentation across agency programs and systems include:
1. identifying an approach, or process, for selecting programs, including
supporting systems to be reviewed;
2. once those programs have been selected, gathering relevant
background information, such as the relationships between the
supporting systems and the data collected to understand if the data
are being duplicated across multiple systems;
3. identifying the potential positive or negative effects of any
fragmentation, overlap, or duplication; and
4. identifying options to increase efficiency and reduce or better manage
any fragmentation, overlap, or duplication and communicating findings
with the appropriate agency officials to determine mitigation efforts,
such as eliminating or consolidating systems.

Page 9

GAO-24-106638 HHS Public Health Data Capabilities


Federal Agencies,
Including HHS, Face
Privacy Challenges

The protection of personal privacy has become a more significant issue in
recent years with the advent of new technologies and the proliferation of
personal information. The increasingly sophisticated ways in which the
federal government obtains and uses PII have the potential to assist in
performing critical functions, such as helping to detect and prevent cyber
threats and enhancing online interactions with the public. However, these
technological developments can also pose challenges in ensuring the
protection of privacy. Recognizing these challenges, we expanded our
existing information security high-risk area to include protecting the
privacy of PII as a high-risk area in 2015. 18 Since then, we have made
186 recommendations in public reports for protecting privacy and
sensitive data across the federal government. As of June 2024, 100 of
these recommendations—two of which were made to HHS—had not
been fully implemented.
We previously reported in September 2022 that HHS did not fully define
or document processes for privacy workforce management. 19 We
recommended that the department fully define and document a process
for ensuring that the senior agency official for privacy (SAOP) or other
designated privacy official is involved in addressing the hiring, training,
and professional development needs of the agency with respect to
privacy. In May 2023, we designated this recommendation as a priority
recommendation. 20 HHS concurred with the recommendation, but as of
June 2024, had not yet implemented it.
Additionally, in December 2022, we reported that HHS’s privacy program
did not have the capability to digitally accept access and consent forms
from individuals that were properly identity proofed and authenticated. 21
We recommended that the department establish a reasonable time frame
for when it will be able to digitally accept these forms from individuals who
were properly identity proofed and authenticated, and post the forms on

18See most recent high-risk list at www.gao.gov/high-risk-list.
19GAO, Privacy: Dedicated Leadership Can Improve Programs and Address Challenges,
GAO-22-105065 (Washington, D.C.: Sept. 22, 2022).
20GAO, Priority Open Recommendations: Department of Health and Human Services,
GAO-23-106467 (Washington, D.C.: May 10, 2023).
21Individuals use access and consent forms to establish their identity and request access
to or provide written consent for the disclosure of their records. GAO, Information
Management: Agencies Need to Streamline Electronic Services, GAO-23-105562
(Washington, D.C.: Dec. 20, 2022).

Page 10

GAO-24-106638 HHS Public Health Data Capabilities


the department’s privacy program website. HHS concurred with the
recommendation, but as of June 2024, had not yet implemented it.

HHS Has Not
Identified and
Reduced
Unnecessary
Duplication, Overlap,
or Fragmentation of
Data in Its Pandemic
Systems

HHS has not developed a comprehensive list of systems supporting
pandemic public health preparedness and response, which is a precursor
to being able to effectively identify unnecessary duplication, overlap, or
fragmentation. Additionally, HHS has not identified and reduced
unnecessary duplication, overlap, or fragmentation among systems
supporting pandemic public health preparedness and response.
Nonetheless, we and others identified examples of duplicative data on
these systems. The shortfalls in HHS’s efforts to identify unnecessary
duplication among its systems is due, in part, to a lack of prioritization.

HHS Has Not Developed a
Comprehensive List of
Systems Supporting
Pandemic Public Health
Preparedness and
Response

The Paperwork Reduction Act in 1995 and the Office of Management and
Budget (OMB) Circular A-130 requires agencies’ CIOs to manage and
inventory information systems that collect data associated with the
agency’s mission, including pandemic systems. 22 Further, the
Consolidated Appropriations Act, 2023 requires HHS and its component
agencies to identify and develop a comprehensive list of pandemic public
health preparedness and response data capabilities. 23
However, HHS’s CIO had not developed a department-wide
comprehensive list of pandemic systems that would include component
agencies’ systems to support pandemic public health preparedness and
response. Since a comprehensive list of pandemic systems did not exist,
at our request, HHS’s relevant component agencies (ASPR, CDC, FDA,
HRSA, IHS, and NIH) identified a total of 99 data collection systems that
support pandemic public health preparedness and response.
However, the lists of systems provided by the component agencies were
inconsistent in nature. For example, system lists for many of the
component agencies did not include relevant pandemic systems, which
raised questions about the comprehensiveness of the lists. For example,
22Paperwork Reduction Act of 1995, Pub. L. No. 104-13, 109 Stat. 172 (44 U.S.C. § 3501

et seq.). Office of Management and Budget, Revised Circular A-130, Managing
Information as a Strategic Resource (Washington, D.C.: July 28, 2016). OMB defines a
major information system as a system that is crucial to an agency’s mission.
23Consolidated Appropriations Act, 2023, Pub. L. No. 117-328, 136 Stat. 5740 (2022).

Page 11

GAO-24-106638 HHS Public Health Data Capabilities


CDC’s initial list of systems that support pandemic public health
preparedness and response did not include previously reported key
pandemic systems: 24
•

COVID-19 Associated Hospitalization Surveillance Network
(commonly referred to as COVID-NET)—used for conducting
surveillance for laboratory confirmed COVID-19-associated
hospitalizations in children and adults;

•

Flu Effectiveness Network—used for estimating the effectiveness of
the vaccines;

•

Epidemic Information Exchange—used for supporting the sharing of
indicator and public health data, such as COVID-19 cases among
CDC, state, territorial, local, and tribal public health departments.

CDC officials stated that these systems were missing from the list due to
an oversight. Subsequently, they updated the list with the missing
systems.
In another example, the IHS system list did not include the Influenza-like
Illness Awareness System. This system collects electronic health record
data from IHS and various tribal sites to detect an increase of influenzalike illness cases in tribal and urban facilities. IHS officials stated that the
system was not initially included because it functions as a syndromic
surveillance system for disease tracking and not as a public health
response and recovery tool. 25 IHS officials subsequently updated their
system list to include the Influenza-like Illness Awareness System
because it supports public health pandemic preparedness and response
through national disease surveillance activities.
Although component agencies updated their systems lists to include
pandemic systems after we identified them, without a department-wide
list, it is uncertain whether all key pandemic systems have been included.
Appendix II includes the list of data collection systems HHS’s component
agencies identified as supporting pandemic public health preparedness
and response.

24GAO-22-104600.
25Syndromic surveillance serves as an early warning system by tracking, in near real-time,
symptoms of patients in emergency departments and other settings before and after a
diagnosis is confirmed. This provides public health officials with a timely system for
detecting unusual levels of illness and understanding and monitoring health events.

Page 12

GAO-24-106638 HHS Public Health Data Capabilities


HHS Has Not Identified
and Reduced
Unnecessary Duplication,
Overlap, or Fragmentation

As previously mentioned, FITARA requires agency CIOs to conduct an
annual review of the agency’s portfolio of IT investments. 26 The review is
to include identifying ways to increase the efficiency of IT investments by
identifying potential duplication, waste, and opportunities to consolidate
the management of IT services. Also, agency CIOs are to identify
potential cost savings from consolidating IT investments and services.
In addition, the Consolidated Appropriations Act, 2023 requires HHS and
its component agencies to identify and reduce unnecessary duplication
among its data capabilities. 27 Further, GAO’s Fragmentation, Overlap,
and Duplication Guide assists agencies with identifying and evaluating
duplication, overlap, and fragmentation to reduce, eliminate, or better
manage negative consequences, such as wasting resources (e.g. time,
money, and appropriate staff). 28 Specifically, the guide recommends that
agency systems are to be reviewed to identify any positive or negative
effects of any duplication, overlap, or fragmentation. Further, any findings
should be developed and communicated with the appropriate agency
officials to determine mitigation efforts, such as eliminating or
consolidating systems.
HHS’s CIO had not conducted department-wide reviews of its various
systems, including those that support pandemic public health
preparedness and response, to identify and reduce any unnecessary
duplication, overlap, or fragmentation. 29 The Office of the CIO and ASPR
officials stated that the HHS IT governance process did not include a
formal process to review its systems to identify and reduce duplication,
overlap, or fragmentation. These officials explained that there were
opportunities in the review process, such as gate and portfolio reviews,
where management officials could ask questions regarding systems’
functions to determine potential duplication. While opportunities might
exist, the departments’ efforts to identify potential duplication, overlap,
and fragmentation were not part of the review process.
26Federal information technology acquisition reform provisions of the Carl Levin and
Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015, Pub.
L. No. 113-291, §833, 128 Stat. 3442 (2014).
27Consolidated Appropriations Act, 2023, Pub. L. No. 117-328, § 2216(a), 136 Stat. 5740

(2022).

28GAO-15-49SP.
29GAO has ongoing work assessing federal agencies’, including HHS, adherence to
FITARA portfolio reviews of IT investments.

Page 13

GAO-24-106638 HHS Public Health Data Capabilities


Instead, HHS relied on its component agencies to perform a review of
their IT systems, including pandemic systems, to identify potential
duplication, overlap, or fragmentation. Two of the six HHS component
agencies that have systems that collect pandemic-related data reported
that they performed reviews to identify unnecessary duplication, overlap,
or fragmentation among their systems. However, these component
agencies did not provide evidence of a review process for identifying
instances of unnecessary duplication, overlap, or fragmentation.
Specifically, CDC officials reported that their systems are reviewed by its
IT and data governance architecture review team. The officials stated that
the team’s review process focuses on standardizing and reducing
duplication among its public health data systems. In addition, according to
CDC officials, the agency’s governance processes conform to the HHS
Policy for Information Technology Acquisition Review under the
requirements of FITARA. However, the documented IT and data
governance architecture review and governance processes did not
include the steps that should be taken, such as identifying the similar
types of data collected, to identify instances of unnecessary duplication,
overlap, or fragmentation. In addition, CDC officials did not provide
evidence that they conducted such a review of their systems.
Further, HRSA officials stated that their systems undergo an annual
review through their resource planning and management process. These
officials stated that the review is to identify duplication among systems
and prevent fragmentation and overlap with existing HRSA systems.
These officials also explained that systems go through an approval
process that involves critical stakeholders, including the HRSA CIO.
However, these processes did not outline the steps for identifying and
reducing unnecessary duplication, overlap, or fragmentation during these
system reviews.
The remaining four component agencies did not provide evidence that
they had established a process to conduct reviews of their systems to
identify duplication, overlap, or fragmentation. Specifically, NIH and IHS
officials stated that a system review was unnecessary because their
systems were unique and only processed pandemic-related data
internally. NIH officials stated that they were part of several meetings with
other agency counterparts and were able to determine that no other
system was similar. Nonetheless, neither NIH nor IHS provided evidence
of an established process to conduct system reviews to identify
unnecessary duplication, overlap, or fragmentation.

Page 14

GAO-24-106638 HHS Public Health Data Capabilities


Additionally, ASPR and FDA did not conduct reviews to identify instances
of duplication, overlap, or fragmentation among its pandemic systems.
Specifically, ASPR officials stated they relied on the HHS IT governance
process for their reviews. However, as noted above, the governance
process did not include a formal review of systems to identify and reduce
duplication, overlap, or fragmentation. Also, according to FDA officials, as
part of their modernization reviews, they identified duplicative data in one
pandemic system. However, they did not have a formal process for
conducting duplication reviews for all of their pandemic systems.
Although HHS relied on component agencies to review their pandemic
systems to identify potential duplication, overlap, and fragmentation, the
component agencies were only able to review duplication within their
systems and not across the department. It is important that the HHS CIO
conducts reviews to ensure that duplication, overlap, and fragmentation
are identified and reduced across various components throughout the
department.

We and Others Identified
Examples of HHS
Component Agency
Systems Collecting
Duplicative Data

We and others found instances of HHS component agencies collecting
duplicative data. Specifically, we found duplication among four systems
that collect pandemic public health preparedness and response data. For
example, two systems—Case Isolate Surveillance (CIS) and Outbreak
Event Surveillance (OES)—function as surveillance systems to track
foodborne outbreaks and provide this information to state health
officials. 30 According to CDC officials, CIS collects individual case
information, while OES collects outbreak, or event-based, aggregate
information. However, both systems collect similar data, such as
hospitalizations and deaths related to foodborne outbreaks. Further,
these data are collected from similar sources, such as state public health
laboratories and epidemiology centers.
In another example, two systems function as a common operating
platform and work together to collect and share data relating to various
disease outbreaks, including COVID-19. Those systems were the Data
Collation and Integration for Public Health Event Response (DCIPHER)
and HHS Protect. Both systems collect similar data, such as COVID-19
30According to CDC officials, the Case Isolate Surveillance system is responsible for

monitoring all national surveillance efforts for the National Center for Emerging and
Zoonotic Infectious Diseases division. Additionally, these officials stated the Division of
Foodborne, Waterborne, and Environmental Diseases Outbreak Event Surveillance within
National Center for Emerging and Zoonotic Infectious Diseases division provides reporting
partners with the ability to enter data about enteric disease outbreaks caused by food,
water, and person-to-person contact, among other things.

Page 15

GAO-24-106638 HHS Public Health Data Capabilities


cases, deaths, laboratory results, and hospitalization data. Further, both
systems are managed by the same CDC program office and utilize the
same cloud-based technology to share information between the
systems. 31
CDC officials acknowledged the similar data collected between the CIS
and OES systems. These officials stated they are developing a
modernization plan to consolidate these systems into DCIPHER. Officials
estimated that the consolidation of CIS would potentially save $75,000
per year in operations and management costs. The officials also
estimated that the consolidation of OES would potentially save $150,000
per year in operations and maintenance costs. 32 This consolidation effort,
according to CDC officials, should be completed by August 2025.
However, CDC has not finalized plans for the consolidation of the
systems into DCIPHER that would describe the costs, data, functions,
and technical resources to be consolidated.
CDC officials also acknowledged the similar functions and the sharing of
data collected between DCIPHER and HHS Protect. According to a plan
dated April 2024, CDC is to consolidate these two systems into a single
common operating platform called CDC Response Ready Enterprise Data
Integration. One of the goals of this consolidation, according to the plan,
is to reduce duplication in the resources for these systems. According to
CDC officials, this consolidation is slated to be complete by August 2025,
but they had not yet identified potential cost savings for completing this
consolidation. 33
In addition to the duplication that we found, representatives from state,
territorial, and local public health organizations also identified an instance
of duplication during the response to the COVID-19 pandemic. These
31Cloud-based technology is based on the concept of cloud computing, which enables on-

demand access to shared computing resources that provide services more quickly and at
a lower cost than if agencies maintained these resources independently.

32According to CDC officials, they provided a notional, predicted potential estimate of
operations and management cost savings for migrating OES into DCIPHER and not the
total cost savings because it would take significant effort to determine the total cost
savings of the migration. They further stated that they do not know the number of years
the potential cost savings would cover for both OES and CIS after the migration.
33CDC officials stated the consolidation of the Data Collation and Integration for Public

Health Event Response into Response Ready Enterprise Data Integration platform has
not begun. CDC officials could not identify a time frame for when the consolidation would
begin. These officials stated that, as a result, it is too early to provide potential cost
savings related to this consolidation.

Page 16

GAO-24-106638 HHS Public Health Data Capabilities


representatives described a situation where state health departments and
hospitals reported COVID-19 data to HHS Protect to track and monitor
COVID-19 cases. They expressed how this led to duplication of COVID19 data because in many cases, the hospitals were already reporting this
data to their respective state health departments, which subsequently
reported this information to CDC.
These representatives stated that the new process placed a burden on
hospital staff because they had to report COVID-19 data to CDC twice
through HHS Protect and their respective state health department and
hospital systems. Further, these representatives stated that HHS Protect
was not interoperable with state health department and hospital systems
which resulted in hospital staff having to, in some cases, manually report
COVID-19 case data to HHS Protect. 34

Shortfalls in
Comprehensive List and
Review Process Are Due,
in Part, to Lack of
Prioritization

HHS’s lack of a department-wide, comprehensive list and review process
for identifying duplicative pandemic systems were due, in part, to the
department not prioritizing these activities. HHS and component agency
officials reported that they had to devote resources to addressing other
priorities, including the COVID-19 pandemic. Since HHS’s CIO did not
assume the responsibility of developing a department-wide,
comprehensive list, there was no foundation for identifying, reducing, or
mitigating the negative effects of duplication across component agency
systems at the department-level.
However, the requirements to develop a comprehensive list of pandemic
systems and conduct reviews to identify duplication are longstanding. As
previously noted, the Paperwork Reduction Act of 1995 requires agency
CIOs to identify and inventory mission-related systems, including
pandemic systems. Further, since 2014, FITARA requires CIOs to review
IT investments to identify duplication and opportunities to consolidate IT
services.
34In August 2021, we reported on HHS Protect hospital capacity reporting requirements

and the challenges experienced by reporting entities, among other things. GAO, COVID19: HHS’s Collection of Hospital Capacity Data, GAO-21-600 (Washington, D.C.: Aug. 5,
2021). In June 2022, we reported that state public health officials most often identified
gaps in interoperability among systems, such as health department systems, as one of
their top challenges related to the management of public health information during the
public health emergency, GAO-22-104600. In September 2020, we reported on
challenges related to sharing data among public health entities, including the lack of an
overall strategy to guide the establishment of interoperability among systems. GAO,
COVID-19: Federal Efforts Could Be Strengthened by Timely and Concerted Actions,
GAO-20-701 (Washington, D.C.: September. 21, 2020).

Page 17

GAO-24-106638 HHS Public Health Data Capabilities


Until HHS’s CIO develops and maintains a department-wide,
comprehensive list of pandemic systems, HHS will miss opportunities to
more efficiently deliver information systems and non-duplicative pandemic
data to users. Further, until the HHS CIO conducts required reviews of
their pandemic systems to identify and reduce unnecessary duplication,
overlap, or fragmentation, HHS and its component agencies may waste
funding and conduct overlapping duties among its systems. This could
delay the department’s response to public health emergencies.

HHS Had Not
Proactively Identified
Funding and Staffing
Resources for Its
Pandemic Systems

HHS and its component agencies had not taken steps to proactively
identify funding sources and costs for all of their pandemic public health
preparedness and response systems. Similarly, HHS and its component
agencies had not taken steps to proactively identify staffing resources for
all of these systems.

HHS and Its Component
Agencies Had Not
Identified Funding Sources
and Costs for Pandemic
Systems

The President’s National Security Memorandum on Countering Biological
Threats, Enhancing Pandemic Preparedness, and Achieving Global
Health Security requires agencies, including HHS, to identify funding
resources in their budget requests allocated to biodefense and pandemic
preparedness. 35 In addition, GAO’s Cost Estimating and Assessment
Guide states that agencies should identify and track costs to ensure that
they are accurate, including funding sources to manage a program.
Further, the guide states that agencies should identify development,
operation, and maintenance costs for its systems. 36
HHS receives funding from a variety of sources to support activities
related to pandemic public health preparedness and response. In 2023,
$81.7 billion was allocated to pandemic preparedness activities. Figure 3
shows examples of the funding sources that the HHS component

35The White House, National Security Memorandum on Countering Biological Threats,
Enhancing Pandemic Preparedness, and Achieving Global Health Security, NSM-15
(Washington, D.C.: Oct. 18, 2022). Biodefense includes actions to counter biological
threats, reduce biological risks, and prepare for, respond to, and recover from biological
incidents.
36GAO-20-195G.

Page 18

GAO-24-106638 HHS Public Health Data Capabilities


agencies identified for the pandemic public health preparedness and
response systems.
Figure 3: Examples of Funding Sources for the Department of Health and Human Services (HHS) Pandemic Public Health
Preparedness and Response Systems

Page 19

GAO-24-106638 HHS Public Health Data Capabilities


Prior to this review, HHS had not taken steps to proactively identify and
track the specific funding sources and costs for each of the systems
supporting pandemic public health preparedness and response. At our
request, the HHS component agencies identified fiscal year 2023 funding
sources and costs for 95 of the 99 (96 percent) data collection systems
that support pandemic public health preparedness and response.
However, not all HHS components track funding sources and costs per
system. Instead, funding is tracked by program. For example, FDA
officials stated that the operation and maintenance costs for 27 of its
pandemic systems are tracked at the program level, which can include
numerous systems, rather than at the system level. So, while FDA could
not identify costs for these 27 systems separately, they were able to
identify total costs for all of the systems under the program they support.
Similarly, CDC officials stated that it could not identify fiscal year 2023
funding sources and costs for one system, CDC Red Sky, because it
shared costs with the Emergency Operations Management System, and
that it would not be feasible to identify the costs between both systems. 37
Nonetheless, of the reported $81.7 billion allocated to pandemic
preparedness activities for fiscal year 2023, the HHS component
agencies reported that approximately $623.4 million was used to operate
and maintain 95 out of 99 (96 percent) of their pandemic systems. 38 Table
1 includes the reported fiscal year 2023 funding sources and total costs
for the five systems with the highest reported costs in fiscal year 2023.
Appendix II includes a list of the HHS data collection systems identified by
component agencies that support pandemic public health preparedness
and response and their reported fiscal year 2023 funding sources and
total costs.

37The CDC Red Sky system gathers data and information about public health events and

displays the data in a real-time dashboard and global map that is intended to track active
health events and improve situational awareness. According to CDC officials, the
Emergency Operations Management System supports CDC’s Emergency Operations
Center, which monitors public health threats. Officials also stated that CDC Red Sky and
the Emergency Operations Management System share costs because they share the
same database.

38The costs provided by the component agencies consisted of both appropriated funds
and obligated funds and varied by component agency.

Page 20

GAO-24-106638 HHS Public Health Data Capabilities


Table 1: Department of Health and Human Services (HHS) Pandemic Public Health Preparedness and Response Systems with
the Greatest Reported Costs in Fiscal Year 2023
HHS
component agencies

Total Fiscal Year 2023
costs (in millions)

System name and description

Fiscal Year 2023 funding source

Centers for Disease
Control and Prevention
(CDC)

Tiberius Platform – provides supply
chain insight to guide medical
countermeasures for COVID-19
and Mpox.

Administration for Strategic
Preparedness and Response funds,
CDC COVID-19 funds, and program
funds.

CDC

National Healthcare Safety Network Appropriated funds, supplemental funds,
– provides tracking and response
and interagency agreements from the
capabilities to identify emerging
Centers for Medicare & Medicaid
and enduring threats across health Services, the Department of Veteran
care (e.g., COVID-19, health care- Affairs, and the Food and Drug
associated infections, and
Administration.
antimicrobial-resistant infections).

$63.4

National Institutes of
Health

National COVID Cohort
Collaborative – collects deidentified
clinical data for COVID-19
research. According to NIH, this
system represents a shared vision
for turning real-world data into the
knowledge needed to address
COVID-19 as the pandemic
evolves.

National Institutes of Health Office of the
Director, Advanced Research Projects
Agency for Health, and National Center
for Advancing Translational Sciences
appropriated funds and Office of the
Assistant Secretary for Planning and
Evaluation funds.

$50.1

CDC

National Syndromic Surveillance
Program – provides a public health
situational awareness network for
outbreaks, disasters, injuries, and
other responses.

Appropriated funds including
Surveillance, Epidemiology, and Public
Health Informatics and Data
Modernization Initiative funds, American
Rescue Plan Act funds, and CDC
Centers, Institutes, and Offices allocated
funds.

$39.3

CDC

U.S. Influenza Vaccine Effectiveness Program funds, COVID-19 funds, and
Networks – estimates the
Prevention and Public Health funds
effectiveness of influenza vaccines
in preventing illness, severe
outcomes, and transmission of
illness.

$84.3

$36.3

Source: GAO analysis of HHS data. | GAO-24-106638

Note: We identified these systems as the five systems with the highest costs, based on the total costs
reported by HHS. The costs provided by the component agencies consisted of both appropriated
funds and obligated funds and varied by component agency.

Although the component agencies identified funding information for most
of their pandemic public health preparedness and response systems at
our request, they did not identify funding sources and costs for all of
them. Specifically, HHS could not provide complete funding information

Page 21

GAO-24-106638 HHS Public Health Data Capabilities


for 4 of the 99 (4 percent) pandemic public health preparedness and
response systems.
As we previously discussed, CDC could not identify funding information
for Red Sky because it shares costs with another system. CDC and IHS
did not provide rationale for why they could not identify complete funding
information for the remaining three systems.

HHS and Its Component
Agencies Had Not
Identified Staffing
Resources

GAO’s IT workforce planning framework indicates agencies should
identify and track staffing resources as well as the amount and type of
staff (i.e., full-time, full-time equivalents (FTEs), contractor, or part-time
staff) dedicated to a system. 39 According to the framework, in order to
have effective team composition, agencies should determine the
necessary skills, team size, and availability of staff. In addition, key
workforce planning activities include developing staffing requirements and
assessing staffing needs regularly.
Prior to this review, HHS had not taken steps to proactively identify and
track staffing resources for its systems, including those supporting
pandemic public health preparedness and response. At our request, the
component agencies identified staffing information for 96 of 99 (97
percent) systems, including the type of staff and number of staff
necessary to operate and maintain them. In some instances, staffing was
identified by program and not by individual system. Therefore, the staffing
levels for these systems varied widely in 2023. For example:
•

IHS officials stated that staffing for the Influenza-like Illness
Awareness System consisted of one FTE and one contractor
dedicated to system maintenance.

•

ASPR officials stated that staffing for the ASPR Ready system
consisted of one FTE and eight contractor staff members. 40

•

CDC officials identified that staffing for the National Healthcare Safety
Network consisted of 34 FTEs and 296 contractor staff members. 41

However, HHS component agencies could not identify complete staffing
information for the remaining three systems (three percent). Officials at
39GAO-17-8.
40According to ASPR officials, ASPR Ready supports agency collaboration and
information and data management for the agency’s preparedness and response missions.
41According to CDC officials, the reported staffing for the National Healthcare Safety
Network includes the staffing for a larger program for which the network supports.

Page 22

GAO-24-106638 HHS Public Health Data Capabilities


the component agencies operating and maintaining the remaining three
systems—one CDC system and two IHS systems—did not provide
rationale for why they could not provide the information.
HHS and the component agencies’ not proactively or consistently
identifying and tracking funding and staffing information for all of their
pandemic systems was due to HHS not prioritizing it. HHS and
component agency officials reported that they had to devote resources to
addressing other priorities, including the COVID-19 pandemic. This issue
is compounded by the fact that the department does not have a
comprehensive list of pandemic systems. Therefore, the department does
not have the foundation necessary for identifying and tracking the funding
and staffing resources for pandemic systems across the department.
Despite the federal government’s response to pandemics, such as
COVID-19, the nation continues to face public health risks for the
foreseeable future. Not being sufficiently prepared for these risks can
negatively affect the time and resources needed to achieve recovery from
future pandemics.
Until HHS is able to proactively and consistently identify and track the
funding resources dedicated to all of its pandemic public health
preparedness and response systems, the department lacks assurance
that it has the funding information needed to effectively manage its
systems at all times in preparation for, during, and after pandemics. This
is critical because many of the funding resources provided for these
systems come from funding provided during the COVID-19 pandemic,
and the future of these funding resources remains uncertain. For
example, all of the component agencies identified instances where future
funding levels may be affected by the loss of pandemic-related funding,
such as funding supplemented by the CARES Act. 42 See appendix III for
a summary of HHS component agencies’ comments on the impact of
pandemic-related funding on their systems.
Further, until HHS proactively and consistently identifies and tracks the
staffing resources dedicated to managing all of its pandemic systems, the
department lacks assurance that it is effectively managing the staffing
resources necessary for preparing for and responding to pandemics. It is
important to determine staffing resources to address pandemic needs
during and outside of pandemic time frames. HHS component agency
officials stated that staff may manage multiple systems and have
42Pub. L. No. 116-136, § 19010, 134 Stat. 579 (2020).

Page 23

GAO-24-106638 HHS Public Health Data Capabilities


additional duties during pandemic response, so it is important that HHS
identifies staffing needs prior to and during pandemics to ensure that the
systems are operating as intended.

HHS Partially
Implemented Key
Privacy Safeguards
for Collecting PII in
Systems Supporting
Pandemic Response

HHS and its component agencies have established officials that are
responsible for privacy activities. However, HHS and its component
agencies have not fully addressed key federal privacy requirements, such
as developing PIAs and privacy plans, for all of their pandemic systems
that include PII. 43

HHS and Its Component
Agencies Established
Officials Responsible for
Privacy

OMB Circular A-130 requires agencies to designate a SAOP responsible
for establishing and maintaining an agency-wide privacy program to
ensure compliance with policies involving protection of PII. 44 Although the
SAOP is responsible for the agency’s privacy program, OMB guidance
provides for the delegation of privacy functions to other qualified agency
personnel, such as senior officials for privacy.
According to the HHS Policy for Information Security and Privacy
Protection, the Chief Information Officer serves as the department’s
SAOP. 45 According to the policy, the SAOP is responsible for ensuring
compliance with privacy requirements, developing and evaluating privacy
policy, and managing privacy risks. In addition, according to HHS policy,
each component agency is to have a senior official for privacy that
supports the HHS SAOP and manages the implementation of privacy
requirements within their component agency. These officials vary for each
component agency; some component agencies have established privacy
positions. For example:

43Personally identifiable information (PII) is any information that can be used to distinguish
or trace an individual’s identity, such as name, date or place of birth, and Social Security
number; or that otherwise can be linked to an individual. A privacy impact assessment
(PIA) analyzes how PII is handled in information systems to ensure that handling
conforms to applicable privacy requirements. A PIA also determines the privacy risks
associated with an information system and evaluates ways to mitigate privacy risks.
44Office of Management and Budget Circular A-130, Managing Information as a Strategic
Resource (Washington, D.C.: July 28, 2016).
45Department of Health and Human Services, HHS Policy for Information Security and

Privacy Protection (Washington, D.C.: Nov. 18, 2021).

Page 24

GAO-24-106638 HHS Public Health Data Capabilities


HHS Component Agencies
Did Not Develop Privacy
Impact Assessments for
Many Pandemic Systems

•

CDC’s senior official for privacy is the Chief Privacy Officer who is to,
among other things, review and approve privacy plans for CDC
information systems before the systems are approved to operate on
the agency’s network.

•

HRSA’s Chief Information Security Officer serves as its senior official
for privacy that oversees privacy compliance activities and leads a
team of privacy officers. According to HRSA officials, these officers
are responsible for conducting PIAs and responding to PII incidents.

•

FDA’s senior official for privacy is responsible for overseeing and
coordinating the component agencies’ privacy compliance efforts,
including approving PIAs before they are sent to the HHS SAOP for
approval.

According to the E-Government Act of 2002 and OMB Memorandum M03-22, Guidance for Implementing the Privacy Provisions of the EGovernment Act, agencies are required to develop a PIA before
developing or procuring IT that store and process PII. In addition,
according to HHS policy, the SAOP requires PIAs to be developed for the
department’s systems that collect and store PII.
However, HHS’s component agencies had not developed PIAs for all of
their pandemic public health preparedness and response systems that
collect and store PII. According to the component agencies, 68 of the 99
(69 percent) systems identified as supporting pandemic public health
preparedness and response collected and stored PII. PIAs were
developed for 53 (78 percent) of these systems, leaving 15 (22 percent)
systems without an assessment of privacy risks.
Seven of the 15 (47 percent) systems that had no PIAs were CDC
systems. CDC stated that PIAs were not required for these systems for
various reasons. For example, CDC officials stated that three of the
seven systems were covered by other systems’ PIAs. However, these
systems were not mentioned in other PIAs as being included in the
assessment. Nonetheless, in May 2024, CDC officials stated that they
had initiated but not yet finalized a separate PIA for one of the three
systems—the Surveillance of Emerging Threats to Pregnant People and
Infants Network. 46

46The Surveillance of Emerging Threats to Pregnant People and Infants Network identifies

the impact of emerging and reemerging health threats, such as COVID-19 on pregnant
people and their infants.

Page 25

GAO-24-106638 HHS Public Health Data Capabilities


For three additional systems, CDC stated that a PIA was not required
because they had either a cooperative agreement or data use agreement
for the information collected and stored by the system. However, CDC
identified these systems as collecting and storing PII. Therefore, a PIA
should have been performed for these systems.
For the last CDC system that lacked a PIA, officials stated that the system
supports various programs across CDC and the programs are to manage
the PIAs for the data they store in the system. However, CDC did not
provide evidence that the programs maintained a PIA for this system.
Seven of the 15 (47 percent) systems that had no PIAs were FDA
systems. In commenting on a draft of this report, FDA officials stated that
these systems were included as part of the PIAs of other systems. 47
However, these seven systems were not mentioned in other PIAs as
being included in the assessment. The officials stated that developing
separate PIAs for every piece of technology used in a system and naming
every piece of technology associated with a system within the applicable
PIA would be unfeasible. However, by not identifying the specific systems
that are to be covered by a privacy assessment, it is unclear whether the
agency has adequately performed assessments on every system that
collects or stores PII.
Regarding the final system, ASPR had completed a PIA for the
Cooperative Agreement Accountability and Management Platform, but it
expired during our audit. 48 According to ASPR officials, a new PIA was
submitted in February 2024 to authorizing officials for review and
approval, but as of July 2024 it had not yet been approved.
Until HHS’s component agencies ensure that privacy risks are assessed
and privacy impact assessments are developed for all of their information
systems containing PII, including those that support pandemic public
health preparedness and response, HHS will have less assurance that it
fully understands the risks and the privacy protections necessary for
these systems.
47One PIA can cover multiple systems that may have common privacy controls. In

addition, some systems can include a variety of sub-systems and may inherit privacy
controls from the larger system.

48According to ASPR officials, the Cooperative Agreement Accountability and

Management Platform supports the management of certain Office of Health Care
Readiness cooperative agreements and supplemental funding.

Page 26

GAO-24-106638 HHS Public Health Data Capabilities


HHS Partially
Implemented Key Privacy
Requirements for Selected
Pandemic Systems That
Include Personal
Information

Federal requirements include several key privacy safeguards for
information systems that include PII. According to the Privacy Act of
1974, agencies are required to have documented system of records
notices (SORN) that notify the public when the agency establishes or
makes changes to a system of records. 49 According to OMB Circular A130, agencies should be transparent about practices in regard to PII and
provide accessible notice to the public regarding the collection, storage,
and disclosure of PII. 50
In addition, according to OMB Circular A-130, agencies should implement
the National Institute of Standards and Technology (NIST) Risk
Management Framework to manage privacy risks related to systems that
include PII. 51 Figure 4 below summarizes the steps for implementing the
NIST Risk Management Framework.

49Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896 (Dec. 31, 1974) (codified as

amended at 5 U.S.C. § 552a). A system of records is a group of records containing
personal information under the control of any agency from which information is retrieved
by the name of an individual or an individual identifier. SORNs are to identify, among other
things, the types of data collected, the types of individuals about whom information is
collected, the intended routine uses of the data, and procedures that individuals can use
to review and correct personal information. The Privacy Act applies to systems of records,
specifically, not all systems containing personally identifiable information.
50Office of Management and Budget Circular A-130, Managing Information as a Strategic

Resource (Washington, D.C.: July 28, 2016).

51National Institute of Standards and Technology SP 800-37, Revision 2: Risk

Management Framework for Information Systems and Organizations: A System Life Cycle
Approach for Security and Privacy (Gaithersburg, Md.: December 2018).

Page 27

GAO-24-106638 HHS Public Health Data Capabilities


Figure 4: Steps for Implementing the Risk Management Framework

HHS partially implemented selected key privacy requirements identified in
the Privacy Act of 1974 and OMB Circular A-130 for the selected
pandemic public health preparedness and response systems that include

Page 28

GAO-24-106638 HHS Public Health Data Capabilities


PII. 52 Figure 5 below summarizes the extent to which HHS’s component
agencies implemented the requirements for nine selected systems. 53

52Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896 (Dec. 31, 1974) (codified as
amended at 5 U.S.C. § 552a). For our review, the key privacy requirements identified in
the Privacy Act of 1974 address implementing systems of records notices. Office of
Management and Budget Circular A-130, Managing Information as a Strategic Resource
(Washington, D.C.: July 28, 2016).
53Our selection of 10 systems included FDA’s Event-based Text-mining for Health

Electronic Records system. FDA had initially stated that the system included PII. After our
review began, FDA analyzed the information stored by the system and determined that it
did not include PII. Therefore, this system was removed from our final evaluation of
privacy requirements, resulting in nine systems. The nine systems were ASPR Ready, the
Electronic Medical Records System, COVID-19 Clearinghouse, DCIPHER, HHS Protect,
Biologics Information Tracking System—Compliance, Human Cell and Tissue
Establishment Registration System, Injury Compensation System, and the National
COVID Cohort Collaborative.

Page 29

GAO-24-106638 HHS Public Health Data Capabilities


Figure 5: The Extent to Which HHS Component Agencies Implemented Key Privacy Requirements for Selected Systems

Note: The systems for each component agency were randomly selected from the agency’s systems
that include personally identifiable information, as identified by the component agencies and are not
generalizable to all of the agencies’ systems.

Develop SORNs. According to the Privacy Act of 1974, agencies are
required to have documented SORNs that notify the public when the
agency establishes or makes changes to a system of records. 54 Figure 6
54Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896 (Dec. 31, 1974) (codified as
amended at 5 U.S.C. § 552a).

Page 30

GAO-24-106638 HHS Public Health Data Capabilities


below summarizes the extent to which the component agencies
developed SORNs for the selected pandemic systems that collect and
store PII.
Figure 6: The Extent to Which HHS Component Agencies Implemented System of Record Notices for Selected Systems

SORNs were developed or the agencies determined they were not
needed for eight of the nine selected pandemic public health
preparedness and response systems collecting and storing PII. For
example:
•

ASPR developed a SORN for ASPR Ready, which includes records
that contain PII, such as home addresses, social security numbers,
and telephone numbers.

•

CDC has an existing SORN that covers the COVID-19 Clearinghouse,
which includes PII from individuals with diseases and other
preventable conditions of public health significance. 55 Records in the
system also include case reports, medical records, and
questionnaires.

•

HRSA developed a SORN for the Injury Compensation System, which
includes medical, medical expense, and employment records used to

55According to CDC officials, the COVID-19 Clearinghouse is a cloud repository for state,

tribal, local, territorial, or national organizations to upload and store COVID-19 vaccination
data.

Page 31

GAO-24-106638 HHS Public Health Data Capabilities


support claims alleging injury or death and to make program
recommendations and decisions. 56
FDA did not develop a SORN for one of the nine systems. Specifically,
FDA did not provide evidence that an assessment was conducted to
determine that a SORN was not required for the Biologics Information
Tracking System – Compliance system. 57 Until FDA conducts an
assessment to determine if SORNs are required for their pandemic
systems that include PII, they lack assurance that they are effectively
informing the public about the department’s use of PII.
SORNs were not applicable for two of the nine systems—the National
COVID Cohort Collaborative and the Human Cell and Tissue
Establishment Registration System. 58 According to FDA and NIH officials,
the Privacy Act did not apply to the selected systems.
Specifically, one selected system, the National COVID Cohort
Collaborative, has a PIA that noted that the system does not contain
personal information for the research data it collects and, therefore, would
not require a SORN. The system’s PIA noted that the system only collects
PII from the users that access the system (e.g., email addresses) and
deidentifies datasets for research. Further, according to the Human Cell
and Tissue Establishment Registration System’s PIA, although the
system contains PII, it does not use names or other personal identifiers
(e.g., an individual’s name, date of birth, and social security number) to
retrieve records.
Develop security categorizations. According to the NIST Risk
Management Framework, agencies should develop security
categorizations for the systems that collect and store PII. Figure 7 below

56According to HRSA officials, the Injury Compensation System collects data from claims

that allege injuries or deaths from certain countermeasures, such as COVID-19 vaccine
and ventilators. Further, its purpose is to provide compensation to individuals for covered
serious injuries or deaths that occur as the direct result of the administration or use of
countermeasures covered by a federal declaration under the Public Readiness and
Emergency Preparedness Act.

57According to FDA officials, the Biologics Information Tracking System – Compliance

system tracks inspections and complaints for biological products.

58According to NIH officials, the National COVID Cohort Collaborative collects deidentified
clinical data for COVID-19 research. According to FDA officials, the Human Cell and
Tissue Establishment Registration System reports on facilities that manage human cells
and tissues.

Page 32

GAO-24-106638 HHS Public Health Data Capabilities


summarizes the extent to which the component agencies developed
security categorizations for the selected systems.
Figure 7: The Extent to Which HHS Component Agencies Developed Security Categorizations for the Selected Systems

System security categorizations were established for six of the nine
selected systems supporting pandemic public health preparedness and
response. The system security categorizations were based on an
assessment of the potential impact that a loss of confidentiality, integrity,
or availability would have on the agency and the public. In addition, the
HHS SAOP reviewed and approved the security categorizations. These
categorizations were documented in the systems’ PIA. Five of the six
systems were categorized as moderate impact systems. The remaining
system, the Electronic Medical Records System, was categorized as a
high impact system. 59

59According to ASPR officials, the Electronic Medical Record System supports the

documentation of all medical care provided during National Disaster Medical System
deployments and enables medical personnel to automate data processes (e.g., data entry
and data reporting). According to these officials, ASPR’s National Disaster Medical
System provides personnel, equipment, and supplies in response to public health
emergencies, including pandemic diseases. In addition, according to these officials, the
Electronic Medical Record System is an application part of the Disaster Medical
Information Suite, a suite of applications used to track National Disaster Medical System
responses.

Page 33

GAO-24-106638 HHS Public Health Data Capabilities


CDC partially developed the system security categorization for two
systems. While CDC developed system security categorizations for its
HHS Protect system and the COVID-19 Clearinghouse, the senior official
for privacy had not reviewed and approved the categorizations. According
to CDC officials, the component agency is currently discussing process
improvement steps for documenting the senior official for privacy’s review
of system security categorizations by September 2024.
FDA partially developed the system security categorization for one
system. While FDA developed the system security categorization for the
Biologics Information Tracking System-Compliance system, the senior
official for privacy had not reviewed and approved the categorization.
According to FDA officials, the senior official for privacy reviews and
approves system security categorizations when they review system PIAs.
However, the component agency had not developed a PIA for this
system. Until CDC and FDA develop security categorizations for the
systems that include PII and document the review and approval of them,
the component agencies have less assurance that they are appropriately
considering the potential impact that a security breach of PII would have
on them and the public.
Develop privacy plans. According to the NIST Risk Management
Framework, agencies should develop privacy plans for the systems that
collect and store PII. Figure 8 below summarizes the extent to which the
component agencies developed privacy plans for the selected systems.

Page 34

GAO-24-106638 HHS Public Health Data Capabilities


Figure 8: The Extent to Which HHS Component Agencies Developed Privacy Plans for the Selected Systems

Privacy plans were developed for eight of the nine selected pandemic
public health preparedness and response systems. These plans
documented the privacy controls in place or planned for the systems. 60
ASPR partially implemented the requirement to develop a privacy plan for
one of the systems we selected from the component agency. Specifically,
ASPR developed a privacy plan for ASPR Ready that included an
overview of privacy requirements. However, the plan did not include the
privacy controls in place or planned for meeting the privacy requirements.
Until ASPR fully develops privacy plans, the component agency is at
increased risk that privacy requirements have not been established, and
therefore, adequate privacy controls may not be place.
Assess privacy controls. According to the NIST Risk Management
Framework, agencies should conduct assessments of privacy controls for
the systems that collect and store PII. Figure 9 below summarizes the
extent to which the component agencies conducted assessments of
privacy controls for the selected systems.

60According to NIH officials, the National COVID Cohort Collaborative is a subsystem

under the National Center for Advancing Translational Sciences General Support System,
which has a privacy plan that includes privacy controls and requirements.

Page 35

GAO-24-106638 HHS Public Health Data Capabilities


Figure 9: The Extent to Which HHS Component Agencies Assessed Privacy Controls for the Selected Systems

Privacy controls were assessed for six of the nine selected pandemic
public health preparedness and response systems. ASPR did not assess
privacy controls for two systems, ASPR Ready and the Electronic Medical
Records System. One reason for this is that, as previously discussed, the
ASRP Ready privacy plan did not include the privacy controls for the
system. Therefore, they did not have information necessary to conduct
the privacy assessment. Since the component agency did not identify the
privacy controls needed for the system, it cannot ensure that it is
effectively assessing the controls. In addition, although ASPR had
documented the privacy controls in the Electronic Medical Records
System’s PIA, it had not yet assessed them. ASPR officials stated that
the privacy assessment for the Electronic Medical Records System is
planned and would be completed by the end of fiscal year 2024.
In addition, we could not find evidence that FDA assessed privacy
controls for one system, the Biologics Information Tracking SystemCompliance. According to FDA officials, the privacy controls were
inherited from another system. 61 However, there was no mention of
61According to NIST, an inherited security control is a situation in which an information

system or application receives protection from security controls (or portions of security
controls) that are developed, implemented, assessed, authorized, and monitored by
entities other than those responsible for the system or application; entities either internal
or external to the organization where the system or application resides.

Page 36

GAO-24-106638 HHS Public Health Data Capabilities


Biologics Information Tracking System-Compliance or its larger
program—the FDA Center for Biologics Evaluation and Research—in that
system’s security assessment report. Until ASPR and FDA fully assess
privacy controls for their systems that collect PII, the component agencies
are at risk of exposing PII collected and stored by these systems, such as
patient medical data.
Develop authorizations to operate. According to the NIST Risk
Management Framework, agencies should develop authorizations to
operate (ATOs) for the systems that collect and store PII. Figure 10 below
summarizes the extent to which the component agencies developed
ATOs for the selected systems.
Figure 10: The Extent to Which HHS Component Agencies Developed Authorizations to Operate for the Selected Systems

ATOs were developed for eight of the nine selected systems. These
ATOs included the approval of their authorizing officials.
However, ASPR did not have evidence of an ATO for the remaining
selected system, the Electronic Medical Record System. According to
ASPR officials, the ATO expired in May 2024. Prior to the expiration, in
February 2024, the component agency submitted a request to the
authorizing official to extend the system’s ATO. However, as of July 2024,
an extension to the ATO had not been approved. Until ASPR develops

Page 37

GAO-24-106638 HHS Public Health Data Capabilities


the authorization to operate, the component agency is operating a system
that contains privacy information without an authorization to do so.
Conduct privacy continuous monitoring. According to the NIST Risk
Management Framework, agencies should regularly monitor privacy
controls for the systems that collect and store PII. The component
agencies conducted privacy continuous monitoring for all nine of the
selected systems. Figure 11 below summarizes the extent to which the
components conducted privacy continuous monitoring for the selected
systems.
Figure 11: The Extent to Which HHS Component Agencies Conducted Monitoring for Privacy Controls for the Selected
Systems

Implementation of most of the six key privacy requirements across the
nine selected systems is a positive step. Nonetheless, until HHS fully
implements key privacy safeguards for protecting PII within pandemic
systems, this information may be at higher risk for unauthorized
disclosure.

Conclusions

Over the last 29 years, HHS’s CIO had the responsibility of developing a
department-wide comprehensive list of systems that collect data
associated with its mission, including those that support pandemic
preparedness and response, and has yet to develop it. Without a
comprehensive list, there was no foundation for conducting reviews to
identify and reduce the negative effects of unnecessary duplication,
overlap, and fragmentation across component agency systems at the

Page 38

GAO-24-106638 HHS Public Health Data Capabilities


department level. Also, without the comprehensive list of these systems,
HHS does not have the foundation for identifying the necessary funding
and staffing resources to manage systems supporting pandemic
preparedness and response. Until HHS conducts required reviews of
these systems to identify duplication, overlap, and fragmentation, the
department may waste resources and unnecessarily perform overlapping
duties among its systems. This could delay the department’s response to
public health emergencies. Further, until HHS proactively and consistently
identifies and tracks funding and staffing resources for these systems, the
department lacks assurance that it has the critical resources needed to
effectively manage its systems in preparation for, during, and after
pandemics.
Longstanding privacy laws and guidance required HHS and its
component agencies to implement privacy safeguards to protect PII, such
as developing PIAs, SORNs, and privacy plans. While HHS and its
component agencies developed PIAs for most of the systems supporting
pandemic preparedness and response that include PII some systems
were left without this assessment. Further, since HHS and its component
agencies have either partially or did not implement key privacy
safeguards for some selected systems that collect PII during pandemics,
the department lacks assurance that its pandemic systems are
adequately protected. Until HHS and the component agencies fully
implement key privacy safeguards for protecting PII within their pandemic
systems, this information may be at higher risk for unauthorized
disclosure.

Recommendations for
Executive Action

We are making a total of 14 recommendations to HHS and the
component agencies:
•

The Secretary of HHS should ensure that the HHS CIO develops and
maintains a department-wide comprehensive list of systems, including
component systems, that support pandemic public health
preparedness and response. (Recommendation 1)

•

The Secretary of HHS should ensure that the HHS CIO conducts
reviews of systems that support pandemic public health preparedness
and response across the department to identify and reduce any
unnecessary duplication, overlap, or fragmentation and identify
mitigation options, such as consolidation or elimination of systems.
The HHS CIO should share the results of its reviews with components
when identifying any instances of unnecessary duplication, overlap, or
fragmentation. (Recommendation 2)

Page 39

GAO-24-106638 HHS Public Health Data Capabilities


•

The Secretary of HHS should ensure that component agencies
proactively and consistently identify and track the funding sources and
costs dedicated to operating and maintaining all of their systems
supporting pandemic public health preparedness and response.
(Recommendation 3)

•

The Secretary of HHS should ensure that component agencies
proactively and consistently identify and track staffing resources,
including the type and number of staff dedicated to managing all of
their systems supporting pandemic public health preparedness and
response. (Recommendation 4)

•

The Secretary of HHS should ensure that the Administration for
Strategic Preparedness and Response has an updated privacy impact
assessment for the Cooperative Agreement Accountability and
Management Platform. (Recommendation 5)

•

The Secretary of HHS should ensure that the Administration of
Strategic Preparedness and Response revises the system privacy
plan for ASPR Ready to include the privacy controls in place or
planned for meeting the privacy requirements. (Recommendation 6)

•

The Secretary of HHS should ensure that the Administration for
Strategic Preparedness and Response develops assessments of
privacy controls for ASPR Ready and the Electronic Medical Records
System. (Recommendation 7)

•

The Secretary of HHS should ensure that the Administration for
Strategic Preparedness and Response develops the authorization to
operate for the Electronic Medical Records System.
(Recommendation 8)

•

The Secretary of HHS should ensure that the Director of the Centers
for Disease Control and Prevention conducts and develops privacy
impact assessments for all pandemic public health preparedness and
response systems that include personally identifiable information.
(Recommendation 9)

•

The Secretary of HHS should ensure that the Director of the Centers
for Disease Control and Prevention ensures that the senior official for
privacy reviews and approves the system security categorizations for
the COVID-19 Clearinghouse and HHS Protect. (Recommendation
10)

•

The Secretary of HHS should ensure that the Commissioner of the
Food and Drug Administration conducts and develops privacy impact
assessments for all pandemic public health preparedness and

Page 40

GAO-24-106638 HHS Public Health Data Capabilities


response systems that include personally identifiable information.
(Recommendation 11)

Agency Comments
and Our Evaluation

•

The Secretary of HHS should ensure that the Commissioner of the
Food and Drug Administration conducts an assessment to determine
if a system of records notice is required for the Biologics Information
Tracking System – Compliance. (Recommendation 12)

•

The Secretary of HHS should ensure that the Commissioner of the
Food and Drug Administration ensures that the senior official for
privacy reviews and approves the system security categorization for
the Biologics Information Tracking System – Compliance.
(Recommendation 13)

•

The Secretary of HHS should ensure that the Commissioner of the
Food and Drug Administration develops an assessment of privacy
controls for the Biologics Information Tracking System – Compliance.
(Recommendation 14)

We provided a draft of this report to HHS for review and comment. The
Assistant Secretary for Legislation provided written comments that are
reprinted in appendix IV and summarized below. HHS and its component
agencies also provided technical comments, which we incorporated as
appropriate.
In its written comments, HHS generally agreed with most of our
recommendations, stating that it would continue to develop required
privacy and security compliance materials for all information systems,
including those noted in our recommendations. It added that going
forward, they would continue to seek opportunities to strengthen their
procedures and compliance with them.
In addition, the department fully concurred with the goal of identifying
duplication, overlap and fragmentation of data systems that support
pandemic response. HHS stated that it would analyze the costs and
benefits for the best way to reduce unnecessary duplication and enhance
efficiencies in public health data systems that support its pandemic
preparedness and response efforts.
HHS did not generally agree with two recommendations (3 and 4).
Specifically, HHS stated that attempting to isolate funding and staffing
information may not be feasible. However, by proactively and consistently
identifying and tracking the resources needed to operate and maintain
HHS’s pandemic public health preparedness and response systems, the

Page 41

GAO-24-106638 HHS Public Health Data Capabilities


department would have increased assurance that it can effectively
manage its systems in preparation for future public health emergencies.
Given the uncertainty of many of the funding sources for these vital
systems, information on the funding and staffing needed to operate and
maintain them will be critical for future success. Accordingly, we continue
to believe our recommendations related to funding and staffing
information are warranted.
The department added that it believed that we may not have fully
considered that the selected HHS systems that we reviewed had public
health data, but that not all of that data is related to pandemic
preparedness and response. Therefore, the department noted, the
purpose of those systems is not solely related to pandemic public health
preparedness and response efforts. We understand that the systems we
reviewed may also be used for other public health efforts and not solely
dedicated to pandemic preparedness and response and noted that in the
report. Nonetheless, HHS would benefit from studying these systems to
determine where duplicative information is being collected or overlapping
activities are being performed by multiple systems. Without such a
review, HHS is limited in their ability to determine where unnecessary
duplication, fragmentation, and overlap may be occurring.
After the completion of our review, several HHS components provided us
with additional information and documentation intended to demonstrate
they had implemented our recommendations related to key privacy
safeguards for protecting PII. This documentation related to
recommendations 6, 12, 13, and 14. We will follow up to confirm that the
actions taken on our recommendations are, to the extent possible,
achieving the desired results. If confirmed, we plan to consider the
recommendations as implemented.
We are sending copies of this report to the appropriate congressional
committees, the Secretary of Health and Human Services, and other
interested parties. In addition, the report is available at no charge on the
GAO website at https://www.gao.gov.

Page 42

GAO-24-106638 HHS Public Health Data Capabilities


If you or your staff have any questions about this report, please contact
Jennifer R. Franks at (404) 679-1831 or franksj@gao.gov. Contact points
for our Offices of Congressional Relations and Public Affairs may be
found on the last page of this report. GAO staff who made key
contributions to this report are listed in appendix V.

Jennifer R. Franks, Director
Center for Enhanced Cybersecurity
Information Technology and Cybersecurity

Page 43

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology
Appendix I: Objectives, Scope, and
Methodology

Our objectives were to determine to what extent has the Department of
Health and Human Services (HHS) (1) identified and reduced
unnecessary duplication, overlap, or fragmentation in its pandemic public
health preparedness and response data capabilities; (2) identified funding
and other resources for the operation of the pandemic public health
preparedness and response data capabilities; and (3) instituted privacy
safeguards when collecting pandemic public health preparedness and
response data.
For all three objectives, we focused on HHS and its component agencies
that maintain systems supporting pandemic public health preparedness
and response. These component agencies include the Administration for
Strategic Preparedness and Response (ASPR), Centers for Disease
Control and Prevention (CDC), Food and Drug Administration (FDA),
Health Resources and Services Administration (HRSA), Indian Health
Service (IHS), and National Institutes of Health (NIH).
For the first objective, we identified Consolidated Appropriations Act,
2023 requirements aimed at identifying and reducing duplication, overlap,
or fragmentation in pandemic public health preparedness and response
data capabilities. 1 HHS and component agency officials reported that
selected agencies maintain systems that support pandemic public health
preparedness and response.
We requested HHS and these component agencies to provide a
department-wide and individual lists of systems that support pandemic
public health preparedness and response, and the data collected by each
system. 2 For each identified system, we requested the data collected by
each system, such as system descriptions, types of data collected, and
data sources. We then compared the lists of systems provided by the
component agencies to systems that support pandemic public health
preparedness and response identified in previously issued GAO reports. 3
1Consolidated Appropriations Act, 2023, Pub. L. No. 117-328, 136 Stat. 5740 (2022).
2For the purposes of this report, the systems we discuss are those that assist HHS in

pandemic preparedness and response, however, these systems could also have other
functions related to public health.

3GAO, COVID-19: Pandemic Lessons Highlight Need for Public Health Situational

Awareness Network, GAO-22-104600 (Washington, D.C.: June 23, 2022) and Public
Health Information Technology, HHS Has Made Little Progress Toward Implementing
Enhanced Situational Awareness Network Capabilities, GAO-17-377 (Washington, D.C.:
Sep 6, 2017).

Page 44

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology

We also identified federal requirements regarding identifying duplication,
overlap, and fragmentation during IT investment portfolio reviews in the
Federal Information Technology Acquisition Reform Act (FITARA) of 2014
and the Consolidated Appropriations Act, 2023. 4 We analyzed the lists of
systems identified by the component agencies to identify areas where
programs may request or collect the same data. We also reviewed HHS
documentation, such as systems IT investment portfolio review plans and
results, and plans to consolidate and retire systems. We then compared
HHS and its components’ efforts to federal requirements on duplication,
overlap, and fragmentation identified in FITARA and the Consolidated
Appropriations Act. We also compared HHS and its component agencies’
efforts to identify and reduce duplication among their systems to key
practices identified in a prior GAO report. 5
We supplemented our analysis with interviews of relevant HHS officials in
ASPR, CDC, FDA, HRSA, IHS, and NIH. We discussed efforts to identify
systems involving pandemic public health preparedness and response
data and their efforts to reduce unnecessary duplication when collecting
these data. In addition, we interviewed representatives from selected
national public health organizations representing state, territorial, and
local public health officials, including the Association of State and
Territorial Health Officials, Council of State and Territorial
Epidemiologists, and National Association of County and City Health
Officials. We discussed the actions the organizations have taken to
collaborate with the department regarding the use of systems that support
pandemic public health preparedness and response and to identify
duplicative systems.
To address the second objective, we identified federal budgetary
requirements and best practices on managing program costs identified in
the National Security Memorandum on Countering Biological Threats,

4Federal information technology acquisition reform provisions of the Carl Levin and

Howard P. ‘Buck’ McKeon National Defense Authorization Act for Fiscal Year 2015, Pub.
L. No. 113-291, 128 Stat. 3442 (2014); Consolidated Appropriations Act, 2023, Pub. L.
No. 117-328, 136 Stat. 5740 (2022).

5GAO, Fragmentation, Overlap, and Duplication: An Evaluation and Management Guide,
GAO-15-49SP (Washington, D.C.: Apr. 14, 2015).

Page 45

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology

Enhancing Pandemic Preparedness, and Achieving Global Health
Security and GAO’s Cost Estimating and Assessment Guide. 6
We analyzed the HHS component agencies’ lists for the reported fiscal
year 2023 funding sources and costs for the 99 systems that support
pandemic public health preparedness and response activities. 7 We also
analyzed system funding documentation, such as budget requests and
contracts. We then compared the reported system funding information
and funding documentation to federal requirements for identifying funding
resources for pandemic preparedness activities and GAO best practices
for developing and managing program costs to determine whether the
funding sources and costs were included. We supplemented our analysis
with interviews with relevant HHS officials in ASPR, CDC, FDA, HRSA,
IHS, and NIH. Further, we assessed the reliability of the agencies’ funding
data by incorporating data reliability questions in our interviews and
correspondence with agency officials. For example, we sought
clarification on how funding data were derived, maintained, and updated,
and how the component agencies ensured their completeness and
accuracy. We found these data to be sufficiently reliable for our reporting
purposes.
Lastly, we identified best practices in GAO’s IT workforce planning
framework. 8 We then analyzed the HHS component agencies’ system
staffing documentation, including program staffing plans, organization
charts, and contracts. We reviewed this information, including the number
of staff and the type of staff (i.e., full-time, full-time equivalent, part-time,
and contractor staff) dedicated to the operation and management of the

6The White House, National Security Memorandum on Countering Biological Threats,

Enhancing Pandemic Preparedness, and Achieving Global Health Security, NSM-15
(Washington, D.C.: Oct. 18, 2022). GAO, Cost Estimating and Assessment Guide: Best
Practices for Developing and Managing Program Costs, GAO-20-195G (Washington,
D.C.: Mar. 12, 2020).

7The costs provided by the component agencies consisted of both appropriated funds and

obligated funds and varied by component agency.

8GAO, IT Workforce: Key Practices Help Ensure Strong Integrated Program Teams;

Selected Departments Need to Assess Skill Gaps, GAO-17-8 (Washington, D.C.: Nov. 30,
2016).

Page 46

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology

pandemic public health preparedness and response systems. 9 We
compared the staffing information to the identified best practices to
determine whether the staffing information was included. We
supplemented our analysis with interviews with relevant HHS officials in
ASPR, CDC, FDA, HRSA, IHS, and NIH.
Further, we assessed the reliability of the staffing data by incorporating
data reliability questions in our interviews and correspondence with
agency officials, such as how staffing data were derived, maintained, and
updated, and how the component agencies ensured their completeness
and accuracy. We found these data to be sufficiently reliable for our
reporting purposes.
For the third objective, we identified federal requirements in the Privacy
Act of 1974 and the E-Government Act of 2002 to identify key
requirements for establishing privacy safeguards. 10 We also identified
requirements for protecting personally identifiable information (PII) in
guidance, including Office of Management and Budget’s (OMB) Circular
A-130: Managing Information as a Strategic Resource, OMB
Memorandum M-03-22, Guidance for Implementing the Privacy
Provisions of the E-Government Act, and National Institute of Standards
and Technology (NIST) Special Publication 800-37 Rev. 2, Risk
Management Framework for Information Systems and Organizations: A
System Life Cycle Approach for Security and Privacy. 11
We then analyzed HHS and the component agencies’ documentation,
including HHS privacy policies and memorandums, and compared the
documentation to federal requirements for establishing dedicated privacy
officials. From the lists of pandemic systems that the HHS component
9A full-time equivalent is a standard measure of labor that reflects the total number of

regular straight-time hours (i.e., not including overtime or holiday hours) worked by
employees divided by the number of compensable hours applicable to each fiscal year.
See the Office of Management and Budget (OMB) Circular No. A-11, Preparation,
Submission, and Execution of the Budget (Washington, D.C.: Aug. 11, 2023).

10Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896 (1974) (codified as amended at 5

U.S.C. § 552a). E-Government Act of 2002, Pub. L. No. 107-347, § 208, 116 Stat. 2899,
2921 (2002) (44 U.S.C. § 3501 note).
11Office of Management and Budget, Managing Information as a Strategic Resource,

Circular A-130 (Washington D.C.: July 28, 2016); OMB Guidance for Implementing the
Privacy Provisions of the E-Government Act of 2002, M-03-22 (Washington, D.C.: Sept.
26, 2003); and National Institute of Standards and Technology SP 800-37, Revision 2:
Risk Management Framework for Information Systems and Organizations: A System Life
Cycle Approach for Security and Privacy (Gaithersburg, Md.: December 2018).

Page 47

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology

agencies provided, they identified 68 systems that included PII. The 68
systems included five ASPR systems, 31 CDC systems, 30 FDA systems,
one HRSA system, and one NIH system. We then assessed all of the
systems the component agencies identified and compared the privacy
impact assessments for the systems against the federal requirements and
guidance for establishing privacy impact assessments for systems that
included PII. We worked with a methodologist to initially select 10
systems based on a random sample of systems from each component
agency’s list of pandemic public health preparedness and response
systems that included PII. Because both HRSA and NIH identified one
system that included PII (i.e., HRSA’s Injury Compensation System and
NIH’s National COVID Cohort Collaborative), we selected those systems
as part of our review. The 10 initially selected systems were:
•

ASPR’s ASPR Ready,

•

ASPR’s Electronic Medical Records System,

•

CDC’s COVID-19 Clearinghouse,

•

CDC’s Data Collation, and Integration for Public Health Event
Response,

•

CDC’s Response Ready Enterprise Data Integration platform,

•

FDA’s Human Cell and Tissue Establishment Registration System,

•

FDA’s Biologics Information Tracking System-Compliance,

•

FDA’s Event-based Text-mining for Health Electronic Records,

•

HRSA’s Injury Compensation System, and

•

NIH’s National COVID Cohort Collaborative.

After our initial selection of 10 systems, we removed FDA’s Event-based
Text-mining for Health Electronic Records system. FDA had initially
included the system as one that included PII. After our review began,
FDA analyzed the information stored by the system and determined that it
did not include PII. Therefore, this system was removed from our final
evaluation of privacy requirements, resulting in nine systems.
We compared security documentation, including system of records
notices, privacy plans and controls, and system authorizations to

Page 48

GAO-24-106638 HHS Public Health Data Capabilities


Appendix I: Objectives, Scope, and
Methodology

requirements for establishing privacy safeguards. 12 The findings from
these systems for each component, while randomly selected, are not
generalizable to all systems in that component. However, for the selected
systems, we were able to assess whether there were instances of the
agencies not meeting all of the privacy requirements. Additionally, we
supplemented our analysis with interviews with relevant HHS officials in
ASPR, CDC, FDA, HRSA, IHS, and NIH.
We conducted this performance audit from February 2023 to September
2024 in accordance with generally accepted government auditing
standards. Those standards require that we plan and perform the audit to
obtain sufficient, appropriate evidence to provide a reasonable basis for
our findings and conclusions based on our audit objectives. We believe
that the evidence obtained provides a reasonable basis for our findings
and conclusions based on our audit objectives.

12E-Government Act of 2002, Pub. L. No. 107-347, § 208, 116 Stat. 2899, 2921 (2002)

(44 U.S.C. § 3501 note); Privacy Act of 1974, Pub. L. No. 93-579, 88 Stat. 1896 (1974)
(codified as amended at 5 U.S.C. § 552a); Office of Management and Budget, Circular A130, Managing Information as a Strategic Resource (Washington, D.C.: July 28, 2016);
and National Institute of Standards and Technology SP 800-37, Revision 2: Risk
Management Framework for Information Systems and Organizations: A System Life Cycle
Approach for Security and Privacy (Gaithersburg, Md.: December 2018).

Page 49

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and
Respond to Pandemic Public Health
Emergencies
Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

In response to public health emergencies, including pandemics, such as
COVID-19, the Department of Health and Human Services uses
pandemic public health preparedness and response systems to collect,
analyze, and share data. The Administration for Strategic Preparedness
and Response, the Center for Disease Control and Prevention, the Food
and Drug Administration, the Health Resources and Services
Administration, the Indian Health Service, and the National Institutes of
Health identified 99 systems that support various pandemic public health
preparedness and response activities.
Table 2 includes the various component agency systems, their
description, fiscal year 2023 funding source and costs from highest to
lowest costs, and staffing information. 1
Table 2: Department of Health and Human Services (HHS) Pandemic Public Health Preparedness and Response Systems
Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System name

System description

System staffing

Centers for
Disease Control
and Prevention
(CDC)

Tiberius Platform

Aggregates COVID-19 data,
including vaccine
therapeutics, and logistics
data, from various U.S.
stakeholders in support of
Operation Warp Speed,
HHS Countermeasures
Acceleration Group, and the
HHS Coordination
Operations Response
Element.

Administration for
Strategic
Preparedness and
Response (ASPR)
funds, CDC COVID19 funding, and
program funds

$84,368,079.00

Total full-time
equivalents
(FTEs): 3
Total
contractors: 80

CDC

National
Healthcare Safety
Network*

Tracks health careassociated infections,
antimicrobial resistant
infections, and antimicrobial
use across health care
settings. Examples of these
data include catheterassociated urinary tract
infections and central-line
associated bloodstream
infections.

Appropriated funding,
supplemental funding,
and interagency
agreements
receivables from
Centers for Medicare
& Medicaid Services,
the Department of
Veterans Affairs, and
the Food and Drug
Administration

$63,400,000.00

Total FTEs: 34
Total
contractors:
296a

1The costs provided by the component agencies consisted of both appropriated funds and

obligated funds and varied by component agency.

Page 50

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

National
Institutes of
Health (NIH)

National COVID
Cohort
Collaborative*

Collects deidentified clinical
data for COVID-19 research.
According to NIH, this
system represents a shared
vision for turning real-world
data into the knowledge
needed to address COVID19 as the pandemic evolves.

NIH Office of the
Director, Advanced
Research Projects
Agency for Health,
and National Center
for Advancing
Translational
Sciences, and Office
of the Assistant
Secretary for Planning
and Evaluation funds.b

$50,100,000.00

Total FTEs: 1
Total
contractors:15

CDC

National
Syndromic
Surveillance
Program

Collects, shares, and uses
electronic health data from
local, state, territorial, and
federal partners to provide
situational awareness for
various public health
responses, such as
outbreaks and disasters.

Appropriated funds
including Surveillance,
Epidemiology, and
Public Health
Informatics, Data
Modernization
Initiative (DMI)
funding, American
Rescue Plan Act
funding, and CDC
Centers, Institutes,
and Offices program
funds.

$39,300,000.00

Total FTEs: 15
Total
contractors: 50

CDC

U.S. Influenza
Vaccine
Effectiveness
Networks*

Estimates the effectiveness
of influenza vaccines in
preventing illness, severe
outcomes, and transmission
of illness.

Program funds,
COVID-19
supplemental funds,
and Prevention and
Public Health Fund

$36,343,813.00

Total FTEs: 14.5
Total
contractors: 3
Fellows: 4

CDC

National
Notifiable
Diseases
Surveillance
System

Tracks data on nationally
notifiable diseases from
approximately 3,000 health
departments across the U.S.

Appropriated funds
including,
Surveillance,
Epidemiology & Public
Health Informatics;
CDC Preparedness &
Response Capability;
DMI funding, and
CARES Act funding

$32,100,000.00

Total FTEs: 33
Total
contractors: 36

Page 51

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System name

System description

CDC

National Vital
Statistics System*

Collects and analyzes data
on vital events like births and
deaths from all 50 states, the
District of Columbia and
New York City, and five
territories.c

Operation funds
(annual
appropriations,
CARES funds, and
DMI funds) and
modernization funds
(CARES funds and
DMI funds, and onetime funding to
jurisdictions to support
National Vital
Statistics System
modernization through
CDC Epidemiology
Laboratory Capacity
Grant).

$31,600,000.00

Total FTEs: 90
Total
contractors: 40

CDC

HHS Protectd*

Serves as the common
operating picture and central
hub to receive, integrate,
and share COVID-19 data in
near real time for the U.S.
government. HHS Protect
also receives national and
state data on COVID-19
cases, laboratory testing,
COVID-19 deaths, hospital
capacity, personal protective
equipment, COVID-19
treatment, and COVID-19
vaccine administration in the
U.S.

CDC Wide Activities,
CARES Act, HHS
funding, ASPR
funding, American
Rescue Plan Act and
Strategic National
Stockpile funding

$28,891,986.28

Total FTEs: 1.5
Total
contractors: 90

CDC

Data Collation
and Integration
for Public Health
Event
Responsed*

Provides a collaborative
environment for routine
public health surveillance
and outbreak responses.

CDC Wide Activities,
CARES Act, HHS
funding,
Administration for
Strategic
Preparedness and
Response funding.
American Rescue
Plan Act and Strategic
National Stockpile
funding

$24,049,638.81

Total FTEs: 1.5
Total
contractors: 90

CDC

Surveillance of
Emerging Threats
to Pregnant
People and
Infants Network*

Identifies the impact of
emerging and reemerging
health threats, such as
COVID-19 on pregnant
people and their infants.

Congressional Base
funding

$23,000,000.00

Total FTEs: 17
Total
contractors: 8
Fellows: 4
Guest
Researcher: 1

Page 52

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System name

System description

CDC

New Vaccine
Surveillance
Network – Acute
Respiratory
Illness

Monitors viral respiratory
infections and associated
syndromes in children less
than 18 years of age across
seven pediatric hospital
systems.

Research cooperative
agreement and
COVID-19 funding

$19,250,000.00

Total FTEs: 3
Total
contractors: 4

Food and Drug
Administration
(FDA)

Adverse Events
and Product
Problems*

Tracks adverse events
related to human cells,
tissues, and cellular- and
tissue-based products and
Center for Biologics
Evaluation and Research
(CBER) regulated devices
and other product problems
in real time.

Base, Prescription
Drug User Fee Act
(PDUFA), and
COVID-19 funding
from the Coronavirus
Response and Relief
Supplemental
Appropriations Act
(CRRSA)

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Biologics
Compliance
Information
System*

Tracks and records data
about Biological Product
Deviation reports, to include
electronic Biological Product
Deviation Reporting and
non-blood reports.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Biologics
Information
Tracking System
– Animal,
Biologics, and
Chemical*

Tracks manufacturers and
suppliers’ information to
provide CBER the ability to
analyze risks related to
ingredients in marketed
products to better respond in
an event of risk to public
health.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Biologics
Investigational
and Related
Application
Management
System*

Tracks the regulatory activity
of Investigational and
Related Applications
submitted to CBER including
new drug applications and
emergency use
authorizations.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Biologics
Information
Tracking System
– Compliance*

Tracks the capture and
processing of complaints
and inspections associated
with CBER’s Office of
Compliance and Biologics
Quality.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Biologics
Information–
Tracking System Device
Submission
Tracking*

Provides CBER with a
modernized web application
for review processes
associated with medical
device submissions.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

Page 53

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Total FTEs: 17
Total
contractors: 150

System staffing

FDA

Biologics
Information–
Tracking System Pre- Application
Tracking*

Tracks sponsor materials
and CBER documents
associated with submissions
that are not an application
type defined in the Code of
Federal Regulations.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

FDA

Biologics
Information–
Tracking System Unlicensed
Requalification
and Variance
Requests*

Tracks and stores
information on Blood Donor
Requalification and Blood
Variance Request document
types.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Blood
Establishment
Registration*

Provides access to
information in an efficient
manner to perform
regulatory mandated
registration of blood
establishments.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Blood Logging
and Tracking*

Maintains information related
to the status and review
progress of applications for
the clearance or approval of
devices and products related
to blood screening,
transfusion, and other
analogous products.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

CBER Adverse
Events Reporting
System*

Analyzes data of individuals
adverse events not
associated with vaccines.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

CBER Connect*

Provides users with the
ability to search, view, and
upload submissions,
communications, and
programmatic items.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

CBER Electronic
Repository*

Stores, retrieves, and
distributes electronic
submissions to reviewers
and interfaces with CBER
regulatory databases.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

CBER Error and
Accident
Reporting
System*

Provides a query-based
system to display and print
information from a database
containing biological product
deviation reports that has
been submitted to CBER.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

Page 54

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Total FTEs: 17
Total
contractors: 150

System staffing

FDA

CBER Regulatory
Meetings
Tracking System*

Tracks Regulatory Meeting
information and internal
CBER meetings and allows
for the generation of
customized reports.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

FDA

Clinical Trials
Modules*

Captures information from
Form FDA 1572 or other
submissions regarding
investigation matters.i

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Electronic Blood
Establishment
Registration
Internet Query*

Uses an internet query to
review non-confidential
Blood Establishment
Registration information for
active, inactive, and preregistered firms.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Electronic Blood
Establishment
Registration
System*

Used by blood product
manufacturers to
electronically register their
establishments and provide
information about the
products they manufacture.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Electronic Human
Cell and Tissue
Establishment
Registration
System*

Used by manufacturers to
electronically register
establishments that engage
in the recovery, processing,
storage, labeling, packaging,
or distribution of any Human
Cells, Tissues, and Cellular
and Tissue-Based Products.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Electronic Human
Cell and Tissue
Establishment
Registration
System Internet
Query*

Uses an internet query to
review non-confidential
Electronic Human Cell and
Tissue Establishment
Registration information for
active, inactive, and preregistered firms.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Event-based
Text-mining for
Health Electronic
Records

Supports ongoing research
initiatives in the fields of text
mining and natural language
processing as a potential
method for semi-automating
the manual review of
spontaneous adverse event
reports provided by Medical
Officers.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

Page 55

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Total FTEs: 17
Total
contractors: 150

System staffing

FDA

Human Cell and
Tissue
Establishment
Registration
System*

Reports on facilities that
have registered with FDA in
compliance with the Federal
Register Notifications for
Human Cells, Tissues, and
Cellular and Tissue-Based
Products Establishment
Registration.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

FDA

Lot Distribution
Database*

Detects potential problems
associated with unusual
concentrations of a particular
adverse event in one or
more production lots for
individual CBER-regulated
products.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Pattern-based
and Advanced
Network Analyzer
for Clinical
Evaluation and
Assessment*

Detects safety signals
associated with vaccines
and provides a new method
for analyzing the large
amounts of data contained in
vaccine spontaneous
adverse event reports in
support of the Vaccine
Adverse Event Reporting
System.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Regulatory –
Management
System Biologics
Licensing
Applications*

Supports CBER’s Managed
Review Process for
reviewing and approving
applications for biological
derived drugs, blood
products, and in vitro
diagnostics Test Kits.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Regulatory –
Management
System Document
Accountability
and Tracking
System*

Supports staff with receipt
and routing of drug
manufacturer submissions to
reviewers and incoming and
outgoing communications.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

FDA

Regulatory
Management
System – Lot
Release System*

Collects meta-data including
test results and protocols
related to physical lots
provided to CBER.

Base, PDUFA, and
CRRSA funding

$16,346,526.71e

Total FTEs: 17
Total
contractors: 150

CDC

Enterprise Data
Analytics and
Visualization
Platform*

Allows staff to store,
analyze, visualize, and
publish data from a single
location for both internal and
external audiences.

CDC’s Working
Capital Fund, DMI,
and program funding

$14,516,046.00

Total FTEs: 2

Page 56

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Collects demographic,
clinical, and outcome data
on laboratory-confirmed
COVID-19 hospitalization
data for children and adults.

COVID-19 funding

$13,600,000.00

Total FTEs: 8
Total
contractors: 2.5

Supply Chain
Control Tower

Monitors and provides endto-end visibility of the U.S.
medical supply chain to
identify supply chain issues
and to inform decisionmaking for HHS leadership,
ASPR, and relevant
agencies.

COVID-19
supplemental funding

$13,000,000.00

Total FTEs: 2.5
Total
contractors: 27

FDA

FDA Adverse
Event Reporting
System*

Contains adverse event
reports, medication error
reports and product quality
complaints resulting in
adverse events that were
submitted to FDA.

User fees and budget
authority

$12,985,384.39

Total FTEs:
11.25
Total
contractors: 66.5

CDC

Vaccine
Administration
Management
System*

Manages various vaccine
administration tasks, such as
patient registration and
appointment scheduling
once the vaccine arrives at
the clinic.

COVID-19
supplemental funding

$11,869,811.00

Total FTEs: 10
Total
contractors: 65

CDC

Active Bacterial
Core Surveillance

Provides an infrastructure for
further public health
research, which may include
special studies to identify
disease risk factors,
evaluate vaccine efficacy,
and monitor the
effectiveness of prevention
policies.

Extramural funding

$10,931,603.00

Total FTEs: 5
Total
contractors: 5

CDC

InfluenzaAssociated
Pediatric Mortality
Surveillance
System*

Collects pediatric mortality
rates associated with
influenza.

National Domestic
Influenza Surveillance
Program fundingf

$10,378,702.40

Total FTEs: 16
Total
contractors: 5
Total CDCfunded state,
tribal, local, and
territorial (STLT)
personnel: 73

System name

System description

CDC

COVID-19
Associated
Hospitalization
Surveillance
Network
(commonly
referred to as
COVID-NET)

ASPR

Page 57

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System name

System description

CDC

Influenza
Virologic
Surveillance –
World Health
Organization
Collaborating
Laboratories and
the National
Respiratory and
Enteric Virus
Surveillance
System*

Monitors influenza activity
data from approximately 100
public health and 300 clinical
laboratories throughout all
50 states, Puerto Rico,
Gaum, and the District of
Columbia.

National Domestic
Influenza Surveillance
Program fundingf

$10,378,702.40

Total FTEs: 16
Total
contractors: 5
Total CDCfunded STLT
personnel: 73

CDC

Surveillance for
Novel Influenza A
Viruses*

Monitors cases of novel
influenza A virus.

National Domestic
Influenza Surveillance
Program fundingf

$10,378,702.40

Total FTEs: 16
Total
contractors: 5
Total CDCfunded STLT
personnel: 73

CDC

U.S. Outpatient
Influenza-like
Illness
Surveillance
Network

Monitors information on
outpatient visits to health
care providers related to
influenza like illnesses.

National Domestic
Influenza Surveillance
Program fundingf

$10,378,702.40

Total FTEs: 16
Total
contractors: 5
Total CDCfunded STLT
personnel: 73

CDC

Vaccine Finder

Shares information about
health care sites and
pharmacies, such as their
locations and COVID-19
inventory data to assist
consumers in obtaining the
vaccine.

COVID-19
supplemental funding

$9,961,714.22

Total
contractors: 35

CDC

Data Lakehouse
Platform

Provides a cloud-based
centralized data respiratory,
which receives COVID-19
data from other internal
systems, to support efforts in
distributing COVID-19
vaccines.

COVID-19 funding
and program funding

$8,681,356.00

Total FTEs: 3
Total
contractors:
30.25

CDC

Influenza
Hospitalization
Surveillance
Network*

Monitors for laboratoryconfirmed influenzaassociated hospitalizations
in children and adults.

Program funding,
Coronavirus and
Other Respiratory
Viruses Division funds

$6,326,265.00

Total FTEs: 3
Total
contractors: 2
Fellows: 2

CDC

National
Wastewater
Surveillance
System

Tracks COVID-19 through
wastewater testing data.

COVID-19 American
Rescue Plan Act
supplemental funds

$6,300,000.00

Total FTEs: 15

Page 58

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System staffing

Collects demographic,
clinical, and laboratory
information from patient
electronic medical records
who visited selected
emergency departments with
acute respiratory illness.

COVID-19 funding

$5,111,077.00

Total FTEs: 3.5

V-Safe*

Shares web-based surveys
with vaccinated individuals
to obtain data to ensure the
safety of vaccines.

COVID-19 funding

$4,290,000.00

Total FTEs: 10
Total
contractors: 10

CDC

Vessel Sanitation
Programg*

Assists to prevent and
control the transmission and
spread of gastrointestinal
illnesses on cruise ships.

Congressional
appropriations, user
fees

$4,000,000.00

Total FTEs:3
Total
Contractors: 1.3

CDC

Respiratory
Syncytial Virus –
Associated
Hospitalization
Surveillance
Network
(commonly
referred to as
RSV-NET)*

Monitors for laboratory
confirmed Respiratory
Syncytial Virus associated
hospitalizations among
children and adults.

Program funding

$4,000,000.00

Total FTEs: 8
Total
Contractors: 2.5

CDC

CDCReady

Collects data associated
with emergency responses,
such as response staffing
and equipment requests.

DMI funding

$3,964,527.55

Total FTEs: 2

FDA

Office of
Regulatory Affairs
Reporting,
Analysis, and
Decisions
Support System*

Provides a central data
warehouse of integrated,
standardized, and cleansed
data for inspections,
shipment histories, samples,
and recalls to conduct
analysis.

Base, PDUFA, and
CRRSA funding

$3,927,000.00

Total FTEs: 1.25
Total
contractors: 15.4

CDC

Vaccine Adverse
Event Reporting
System*

Monitors for unusual or
unexpected reporting
patterns of adverse events
following a patient’s
vaccination.

Vaccine Adverse
Event Reporting
System core funding,
National Center for
Immunization and
Respiratory Diseases
Pan Flu funding,
National Center for
Immunization and
Respiratory Diseases
Vaccines for Children
funding, and COVID19 funding

$3,843,448.00

Total FTEs: 8
Total
contractors: 53

System name

System description

CDC

Respiratory Virus
Laboratory
Emergency
Department
Surveillance*

CDC

Page 59

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Collects responses from
health centers to track
capacity and the impact of
COVID-19 on the health
center operations, patients,
and staff.

Funding for the
Bureau of Primary
Health Care’s use of
the Salesforce
platform

$3,589,941.00

Total FTEs: 2
Total
contractors: 1

National
Molecular
Subtyping
Network for
Foodborne
Disease
Surveillance
(commonly
referred to as
PulseNet)

Serves as a national network
of public health laboratories
that perform DNA
fingerprinting of food-borne
bacteria to detect outbreaks.

Division and
Advanced Molecular
Detection funding

$3,500,000.00

Total FTEs: 12
Total
contractors: 10
Fellows: 6

ASPR

Health Partner
Order Portal

Manages, monitors, and
reports data associated with
the ordering and distribution
of vaccines deemed critical
to national emergency, such
as COVID-19.

HHS Coordination
Operations and
Response Element
programmatic dollars

$3,500,000.00

Total FTEs: 1
Total
contractors: 4

ASPR

ASPR Ready*

Streamlines agency
collaboration, information,
and data management, and
provides the Common
Operating Picture for
ASPR’s preparedness and
response missions.

Med-Surge
supplemental funding,
COVID-19
supplemental funding,
HHS Coordination
Operations and
Response Element
fiscal year funding

$3,000,000.00

Total FTEs: 1
Total
contractors: 8

CDC

National Human
Immunodeficiency
Virus (HIV)
Behavioral
Surveillance –
Data Coordinating
Center and Webbased Integrated
Surveillance
Management
System*

Supports two key HIV
surveillance systems in
collecting patient data, such
as demographics and sexual
behaviors.

Operations and
maintenance (O&M)Data Coordination
Center, Development,
Modernization, and
Enhancement-Data
Coordination Center,
and O&M-Web-based
Integrated
Surveillance
Management System
contract costs

$2,812,327.00

Total FTEs: 14
Total
contractors: 6.5

System name

System description

Health
Resources and
Services
Administration
(HRSA)

The Health
Center COVID-19
Survey

CDC

Page 60

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System name

System description

CDC

COVID-19
Clearinghouse*

Provides a secure space for
state, tribal, local, or
territorial jurisdictions and
other National Provider
Organizations to upload and
store COVID-19 vaccination
data collected from provider
organizations systems, such
as electronic health records.

CRRSA

$2,749,629.00

Total FTEs: 1.5
Total
contractors: 4.5

NIH

OpenData
COVID-19 Portal

Shares COVID-19 drug
screening data, including
from the National Center for
Advancing Translational
Sciences, to improve the
access to drug testing data
needed by the research
community to address
COVID-19.b

COVID-19
supplemental funding

$2,200,000.00

Total FTEs: 1
Total
contractors: 4

CDC

Influenza Lab
Information
Management
System*

Supports sharing, storing,
and analyzing laboratory and
epidemiology-related data.

Program funding and
Coronavirus and
Other Respiratory
Viruses Division
funding

$1,982,841.00

Total FTEs: 1
Total
contractors: 6

CDC

National HIV
Case Surveillance
– Enhanced HIV
Acquired
immunodeficiency
syndrome
Reporting
System*

Collects, stores, and
manages HIV case
surveillance data from
various jurisdictional
partners.

Contract funding
including tasks of
project management,
system O&M, and
user support

$1,620,000.00

Total
contractors: 9

FDA

506J Database*

Collects and stores
information from
manufacturers during a
public health emergency
regarding supply chain
disruptions and product
discontinuances of medical
devices.

COVID-19
supplemental funding

$1,326,646.00

Total FTEs: 0.5
Total
contractors: 5.25

CDC

National
Tuberculosis
Surveillance
System*

Supports the integration of
data from state operated
Tuberculosis programs using
common and custom
developed data collection
tools.

Contract funding
including tasks of
project management,
system O&M, system
Development,
Modernization and
Enhancement, and
user support

$1,304,000.00

Total
contractors: 0.6

Page 61

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

System staffing

ASPR

Electronic
Medical Record
System*

Reports of all medical care
provided during a national
disaster deployment and
enables automation of
medical logistics data-entry,
collection, retrieval, reporting
and transfer.

Annual appropriations
and COVID-19
supplemental funding

$1,095,892.00h

ASPR

Joint Patient
Assessment
Tracking System*

Provides real time
accountability of patients
seen by emergency support
personnel by tracking every
patient moved by the federal
government through all
phases of the patient’s
movement.

Annual appropriations
and COVID-19
supplemental funding

$1,095,892.00h

Total
contractors: 7

ASPR

Response
Management
System*

Manages, prepares, trains,
and tracks responders
deployed for disasters and
national special security
events.

Annual appropriations
and COVID-19
supplemental funding

$1,095,892.00h

Total
contractors: 7

CDC

Epidemic
Information
Exchange*

Provides web-based
communications to connect
public health professionals
involved in identifying,
investigating, and
responding to public health
threats.

CARES Act

$1,085,587.20

Total FTEs: 3
Total
contractors: 5

CDC

National
Notifiable
Diseases
Surveillance
System Analytic
Database*

Collects epidemiological and
clinical information such as
demographics,
hospitalization, and
vaccination history to
transform into an analyzable
dataset.

Program funding

$1,083,812.48

Total FTEs: .5
Total
contractors: 5.5

HRSA

Injury
Compensation
System*

Stores medical expense and
employment records used to
support claims of patients
alleging injuries or deaths
from countermeasures, such
as COVID-19 vaccines and
ventilators.

Annual appropriationsi

$836,434.00

Total FTEs: 9

CDC

National HIV
Case Surveillance
– Secure HIVTransmission
Cluster Engine

Provides a tool for health
departments to analyze
genetic sequences and other
data collected by the
National HIV Surveillance
System.

Contract funding
including tasks of
project management,
system O&M, system
Development,
Modernization, and
Enhancement, and
user support

$720,000.00j

Total
contractors: 2.4

Page 62

Total
contractors: 7

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

Collects public health
incident and federal disaster
information from response
partners and open sources
to create geospatial visuals
(e.g., maps and dashboards)
for enhanced situational
awareness capabilities.

Fiscal year funding

$650,075.00

Total FTEs: 2
Total
contractors: 8

National Arboviral
Surveillance
System*

Collects reported arboviral
disease cases from state
health departments to
combine the data and
provides mapping
capabilities.

Programmatic funding

$634,503.00

Total FTEs: 3.3

CDC

Outbreak Event
Surveillance

Provides various reporting
partners (e.g., state health
departments and reporting
site administrators at the
state and local level) the
ability to enter data about
enteric disease outbreaks
caused by food, water,
animal, and person-toperson contact.

Program funding

$500,000.00

Total FTEs: 6
Total
contractors: 3
Fellows: 3

CDC

Vessel Sanitation
Program
Inspection
Reporting
Systemg*

Collects administrative
information and provides a
platform to schedule and
conducts ship inspections
and releases inspection
scores.

Congressional
appropriations, user
fees

$500,000.00

Total FTEs: 4
Total
contractors: 1

CDC

Maritime Illness
Database
Reporting
Systemg*

Receives information
electronically through a webbased reporting portal
related to acute
gastroenteritis cases during
the duration of a ship’s
voyage.

Congressional
appropriations, user
fees

$500,000.00

Total FTEs: 4
Total
Contractors: 1

Indian Health
Service (IHS)

Influenza-like
Illness Awareness
System

Collects select electronic
health record data sourced
from participating IHS and
tribal sites that utilize the
IHS Electronic Health
Record system.

One-time CARES Act
funds

$466,880.40

Total FTEs: 0.05
Total
contractors: 1

System name

System description

ASPR

GeoHealth/
Geospatial Health
System

CDC

Page 63

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

CDC

CryptoNet

Facilitates the sharing of
laboratory data among state
and local public health
laboratories to improve the
investigations of foodborne
and waterborne outbreaks of
cryptosporidiosis in the
United States.

Advanced Molecular
Detection and
Emerging Infectious
Diseases and Food
Safety Program funds

$456,000.00

Total FTEs: 2
Total
contractors: 3
Fellows: 1

CDC

Dengue
Laboratory
Sample
Database*

Monitors occurrences of
dengue in Puerto Rico and
uses a database to contain
patient information and
laboratory results from the
dengue diagnostic lab.

Programmatic funding

$405,938.00

Total FTEs: 4.95

CDC

National Rabies
Surveillance
System

Collects laboratory reporting
data associated with animal
rabies.

Emerging Infectious
funds

$340,000.00

Total FTEs: 1

CDC

Viral Hepatitis
Surveillance –
Global Hepatitis
Outbreak
Surveillance
Technology

Allows public health
laboratories to upload viral
sequences via a web-based
tool, to rapidly respond to
outbreaks of hepatitis C.

Contract funding
including tasks of
project management,
system O&M, and
user support

$303,000.00

Total
contractors: 4.3

CDC

National
Respiratory and
Enteric Virus
Surveillance
System

Monitors circulation patterns
of respiratory and enteric
viruses.

National Disease
Surveillance Program
funding

$270,985.00

Total FTEs: Not
available
Total
contractors: Not
available

CDC

MicrobeNet*

Consolidates information
and provide access to CDC
subject matter expertise to
outside stakeholders such
as public health laboratories
related to bacterial and
fungal pathogens.

Global Public Health
Protection funding and
CDC Preparedness
and Response funding

$248,359.33

Total FTEs: 3
Total
Contractors: 1

ASPR

Cooperative
Agreement and
Accountability
Management
Platform*

Supports the management
of certain Office of Health
Care Readiness cooperative
agreements and
supplemental funding.

Health Care
Readiness and
Recovery budget line

$199,999.72

Total FTEs: 0.5
Total
contractors: 0.5

ASPR

HHS emPOWER
Map

Operates as a public,
interactive map that displays
monthly updated population
data for at-risk Medicare
beneficiaries that use certain
types of life-maintaining
electricity-dependent
medical equipment, devices,
and health care services.

National Disaster
Medical System
annual appropriation
funding

$104,824.00

Total FTEs: 1
Total
Contractors: 2

Page 64

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Component
agency

System name

System description

Fiscal Year 2023
funding source

Fiscal Year
2023 cost

CDC

National
Antimicrobial
Resistance
Monitoring
System

Collects susceptibility data
on foodborne and diarrheal
organisms (Salmonella,
Shigella, E. Coli,
Campylobacter, noncholerae Vibrio).

Program funding,
Combating Antibiotic
Resistant Bacteria,
and Advanced
Molecular Detection
funding

$100,000.00

Total FTEs: 6
Total
contractors: 3
Fellows: 3

CDC

Global Emerging
Infections
Sentinel Network

Collects travel related data
from selected members of
the International Society of
Travel Medicine sites around
the world to monitor travel
associated diseases.

Appropriated funding

$100,000.00

Total
contractors: 2

FDA

Allegation of
Regulatory
Misconduct
Online Report
Form*

Collects allegations of
regulatory
misconduct/complaints from
medical device
manufacturers, consumers,
health care workers and
other entities from the public.

Budget authority

$34,284.00

Total
contractors: 2

CDC

Drug Activity
Reporting
System*

Provides inventory
management and record
keeping associated with
restricted pharmaceutical
and biologics released from
CDC Drug Service.

Program funding and
DMI supplemental
funding

$28,150.00

Total FTEs: 4
Total
contractors: 3

CDC

Case Isolate
Surveillance*

Contains all national
surveillance efforts including
enhanced case surveillance
data and laboratory-based
surveillance.

Not available

Not available

Total FTEs: 2
Total
contractors: 3
Fellows: 4

CDC

CDC Red Sky

Gathers data and
information about public
health events and displays
the data in a real-time
dashboard and global map
that is intended to track
active health events and
improve situational
awareness.

Not available

Not available

Total FTEs: 1
Total
contractors: 5

IHS

Central
Aggregator
Server

Collects and combines data
from various IHS federal and
tribal systems.

Not available

Not available

Total FTEs: Not
available
Total
contractors: Not
available

IHS

COVID-19
Disease
Surveillance
Reporting
Systems

Provides the agency insights
into COVID testing and
immunization tracking of
data reported by electronic
health record systems.

Not available

Not available

Total FTEs: Not
available
Total
contractors: Not
available

Page 65

System staffing

GAO-24-106638 HHS Public Health Data Capabilities


Appendix II: HHS Component Agencies Use
Various Systems to Prepare for and Respond
to Pandemic Public Health Emergencies

Legend: * = systems the component agencies identified as including personally identifiable information.
Source: GAO analysis of HHS data. | GAO-24-106638

Note: The costs provided by the component agencies consisted of both appropriated funds and
obligated funds and varied by component agency.
a
According to CDC officials, the reported staffing for the National Healthcare Safety Network includes
the staffing for the larger National Healthcare Safety Network program.
b
The National Center for Advancing Translational Sciences mission is to turn research observations
into health solutions through translational science. The vision is more treatments for all people more
quickly.
c
The five territories are Puerto Rico, the U.S. Virgin Islands, Guam, American Samoa, and the
Commonwealth of the Northern Mariana Islands.
d
According to the CDC officials, CDC HHS Protect is managed through a program management office
that supports both the Data Collation and Integration for Public Health Event Response (DCIPHER)
and HHS Protect.
e
According to FDA officials, $16,346,526.71 is the cost for all 27 CBER systems in the list. According
to these officials, it is not possible to report the cost of each individual system. In addition, these
officials stated that the 17 FTES and 150 contractors work on all of the CBER systems and are not
assigned to individual systems.
f
Total fiscal year 2023 funding for the entire National Domestic Influenza Surveillance Program (i.e.,
all components) consists of $10,378,702.40. The 16 FTEs, 5 contractors, and 73 STLT personnel
cover all systems in the program.
g
The Vessel Sanitation Program data system consists of the two applications (i.e., Vessel Sanitation
Program Inspection Reporting System and the Maritime Illness Database Reporting System).
Program total appropriations in FY23 were $4 million, which includes all staffing/other costs
associated with conduction cruise ship inspections. The approximate estimate for operating Vessel
Sanitation Program Inspection Reporting System and Maritime Illness Database Reporting System is
$500,000. The 4 FTEs and 1 contractor covers the entire system.
h
According to ASPR officials, the funding for the National Disaster Medical System applications (i.e.,
the Electronic Medical Record System, the Joint Patient Assessment and Tracking System, and the
Response Management System) consists of $1,095,892.00. In addition, a team of seven contractors
provides staffing support across the National Disaster Medical System Application Suite.

The Injury Compensation System’s first direct appropriation was in FY 2022.

i

According to CDC officials, the cost for HIV-Transmission Cluster Engine is estimated, and the
contract has not been awarded yet.

j

Page 66

GAO-24-106638 HHS Public Health Data Capabilities


Appendix III: HHS Component Agency
Comments on the Impact of Pandemic
Funding
Appendix III: HHS Component Agency
Comments on the Impact of Pandemic Funding

The Department of Health and Human Services (HHS) component
agencies provided comments on how future funding levels may be
impacted by the loss of pandemic-related funding, such as funding
supplemented by the CARES Act. Specifically,
•

Officials from the Administration for Strategic Preparedness and
Response stated that the component agency has made improvements
in data management and data analytics capabilities throughout the
COVID-19 response. According to the officials, no longer having
COVID-19 funding would significantly reduce HHS’ ability to collect,
share, and analyze data, and would limit interoperability with other
jurisdictional and federal systems.

•

Officials from the Centers for Disease Control and Prevention stated
that enhancements have been made to data collection and reporting,
data processing and management, and data analytic capabilities
during the COVID-19 public health emergency response with COVID19 supplemental funding. According to the officials, the loss of
COVID-19 supplemental funding would significantly reduce HHS’
long-term ability to collect, manage, share, and analyze data for
response and would slow data system modernization. These officials
stated that they are assessing the sustainability of current capabilities
using other funding sources, including program funding and other
appropriations, but that significant gaps in funding would remain.

•

Officials from the Food and Drug Administration stated that the
component agency received $105 million as one-time, supplemental
funding to address the COVID-19 pandemic. The officials stated that
the funds went towards a postmarket surveillance program during the
pandemic. 1 According to these officials, the remaining supplemental
funds were obligated in fiscal year 2023, so the scope of the program
will be reduced for fiscal year 2024.

•

Officials from the Health Resources and Services Administration
stated that COVID-19 funding for the Countermeasures Injury
Compensation Program is projected to be exhausted by the end of

1Postmarket refers to the time period after introduction of a device into the market for

patient and provider use.

Page 67

GAO-24-106638 HHS Public Health Data Capabilities


Appendix III: HHS Component Agency
Comments on the Impact of Pandemic Funding

fiscal year 2024. 2 According to these officials, the lack of additional
funding could impact necessary future upgrades and maintenance
and may cause slow processing times for the program.
•

Officials from the Indian Health Service stated that the component
agency obligated large percentages of COVID-19 supplemental
funding to combat the pandemic and to address the component
agency’s infrastructure needs. These officials stated that the lack of
these funds has impacted the component agency’s ability to invest in
long-term improvements, such as public health infrastructure grants.

•

Officials from the National Institutes of Health also expressed funding
challenges with their systems, such as the National COVID Cohort
Collaborative. 3 The officials stated that the lack of sustained and
dedicated funding could result in the loss of staff and limit system
operations and maintenance of key pandemic systems.

2According to officials from the Health Resources and Services Administration, the

Countermeasures Injury Compensation Program collects data from claims that allege
injuries or deaths from certain countermeasures, such as COVID-19 vaccine and
ventilators. Further, its purpose is to provide compensation to individuals for covered
serious injuries or deaths that occur as the direct result of the administration or use of
countermeasures covered by a federal declaration under the Public Readiness and
Emergency Preparedness Act.

3According to officials from the National Institutes of Health, the National COVID Cohort

Collaborative collects deidentified clinical data for COVID-19 research. According to NIH,
this system represents a shared vision for turning real-world data into the knowledge
needed to address COVID-19 as the pandemic evolves.

Page 68

GAO-24-106638 HHS Public Health Data Capabilities


Appendix IV: Comments from the
Department of Health and Human Services
Appendix IV: Comments from the Department
of Health and Human Services

Page 69

GAO-24-106638 HHS Public Health Data Capabilities


Appendix IV: Comments from the Department
of Health and Human Services

Page 70

GAO-24-106638 HHS Public Health Data Capabilities


Appendix V: GAO Contact and Staff
Acknowledgments
Appendix V: GAO Contact and Staff
Acknowledgments

GAO Contact

Jennifer R. Franks at (404) 679-1831 or franksj@gao.gov

Staff
Acknowledgments

In addition to the contact named above, Freda Paintsil (Assistant
Director), Darron Smallwood (Analyst in Charge), Ibrahim Suleman
(Analyst in Charge), Deirdre Brown, Jillian Clouse, Donna Epler, Hayden
Huang, Franklin Jackson, Nicole Jarvis, Smith Julmisse, Susanna
Kuebler, Susan Murphy, Amber Sinclair, Shannon Slawter Legeer, Adam
Vodraska made key contributions to this report.

Page 71

GAO-24-106638 HHS Public Health Data Capabilities


GAO’s Mission

The Government Accountability Office, the audit, evaluation, and investigative
arm of Congress, exists to support Congress in meeting its constitutional
responsibilities and to help improve the performance and accountability of the
federal government for the American people. GAO examines the use of public
funds; evaluates federal programs and policies; and provides analyses,
recommendations, and other assistance to help Congress make informed
oversight, policy, and funding decisions. GAO’s commitment to good government
is reflected in its core values of accountability, integrity, and reliability.

Obtaining Copies of
GAO Reports and
Testimony

The fastest and easiest way to obtain copies of GAO documents at no cost is
through our website. Each weekday afternoon, GAO posts on its website newly
released reports, testimony, and correspondence. You can also subscribe to
GAO’s email updates to receive notification of newly posted products.

Order by Phone

The price of each GAO publication reflects GAO’s actual cost of production and
distribution and depends on the number of pages in the publication and whether
the publication is printed in color or black and white. Pricing and ordering
information is posted on GAO’s website, https://www.gao.gov/ordering.htm.
Place orders by calling (202) 512-6000, toll free (866) 801-7077, or
TDD (202) 512-2537.
Orders may be paid for using American Express, Discover Card, MasterCard,
Visa, check, or money order. Call for additional information.

Connect with GAO

Connect with GAO on Facebook, Flickr, Twitter, and YouTube.
Subscribe to our RSS Feeds or Email Updates. Listen to our Podcasts.
Visit GAO on the web at https://www.gao.gov.

To Report Fraud,
Waste, and Abuse in
Federal Programs

Contact FraudNet:
Website: https://www.gao.gov/about/what-gao-does/fraudnet
Automated answering system: (800) 424-5454 or (202) 512-7700

Congressional
Relations

A. Nicole Clowers, Managing Director, ClowersA@gao.gov, (202) 512-4400, U.S.
Government Accountability Office, 441 G Street NW, Room 7125, Washington,
DC 20548

Public Affairs

Sarah Kaczmarek, Acting Managing Director, KaczmarekS@gao.gov, (202) 5124800, U.S. Government Accountability Office, 441 G Street NW, Room 7149
Washington, DC 20548

Strategic Planning and
External Liaison

Stephen J. Sanford, Managing Director, spel@gao.gov, (202) 512-4707
U.S. Government Accountability Office, 441 G Street NW, Room 7814,
Washington, DC 20548

File and source

File
24-106638-covid-19-hhs-needs-to-identify-duplicative.pdf
Size
4,419,363 bytes
SHA-256
2c97e734394d9397266b062a84ba8028a69fadf6a812a11a1d69c644796872b5
Our copy
24-106638-covid-19-hhs-needs-to-identify-duplicative.pdf
Original
www.gao.gov
Back to top