Skip to main content
U.S. flag

An official website of the United States government

Here’s how you know

Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

HTTPS

Secure .gov websites use HTTPS
A lock (LockA locked padlock) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

    • Environmental Topics
    • Air
    • Bed Bugs
    • Cancer
    • Chemicals, Toxics, and Pesticide
    • Emergency Response
    • Environmental Information by Location
    • Health
    • Land, Waste, and Cleanup
    • Lead
    • Mold
    • Radon
    • Research
    • Science Topics
    • Water Topics
    • A-Z Topic Index
    • Laws & Regulations
    • By Business Sector
    • By Topic
    • Compliance
    • Enforcement
    • Laws and Executive Orders
    • Regulations
    • Report a Violation
    • Environmental Violations
    • Fraud, Waste or Abuse
    • About EPA
    • Our Mission and What We Do
    • Headquarters Offices
    • Regional Offices
    • Labs and Research Centers
    • Planning, Budget, and Results
    • Organization Chart
    • EPA History

Breadcrumb

  1. Home
  2. Privacy Act

How Contractors Will Respond to a Suspected or Confirmed PII Breach

Contractor Responsibilities and Reporting Procedures

Introduction and Overview

The Environmental Protection Agency (EPA) developed the following procedures for contractors to follow when a suspected or known breach of personally identifiable information (PII) has occurred.

Reporting Incidents

Pursuant to EPA’s Privacy Policy , contractors are responsible for immediately reporting any suspected or known breach of personally identifiable information (PII) as soon as the incident is discovered to the EPA Call Center at 1-866-411-4372. In addition, the contractor shall inform the Contracting Officer and the Contracting Officer Representative immediately thereafter that the EPA Call Center has been notified of a potential breach of PII. III.

The EPA Call Center

The EPA Call Center will perform the initial assessment of the incident to determine if there has been a breach of PII. At a minimum, the contractor shall provide the following information when contacting the Call Center: the type of PII, how and where PII was stored, number of people affected, the individual(s) responsible, who reported it and the date of occurrence. The Call Center will immediately forward the incident report for investigation.

Full Cooperation

The contractor shall cooperate fully with Agency personnel during the investigation and assist in the containment, control and safeguarding of information to prevent the breach from re-occurring, if requested by the Agency. Failure to take appropriate action upon discovering the breach, take required steps to prevent a breach from occurring, notify the Agency, or cooperate in the investigation may result in disciplinary actions, parallel law enforcement investigations, or litigation.

Terms and Definitions

  • Personally Identifiable Information (PII) is any information maintained by the Agency, which can be used to distinguish, trace, or identify an individual’s identity, including personal information which is linked or linkable to an individual. Legal name is an example of commonly used PII.
  • Sensitive Personally Identifiable Information is a subset of PII and includes a person’s Social Security numbers, or comparable identification numbers, financial information and/or medical information associated with an individual.
  • Breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access by persons without authorized access or potential access to PII or Privacy Act information, whether physical or electronic.

Privacy Act

  • Overview
  • Federal Information Systems
  • Laws, Policies & Resources
  • Privacy & Security Notice
  • Submit Privacy Request
Contact Us about the Privacy Act
Contact Us to ask a question, provide feedback, or report a problem.
Last updated on September 3, 2024
  • Assistance
  • Spanish
  • Arabic
  • Chinese (simplified)
  • Chinese (traditional)
  • French
  • Haitian Creole
  • Korean
  • Portuguese
  • Russian
  • Tagalog
  • Vietnamese
United States Environmental Protection Agency

Discover.

  • Accessibility Statement
  • Budget & Performance
  • Contracting
  • EPA www Web Snapshot
  • Grants
  • No FEAR Act Data
  • Plain Writing
  • Privacy
  • Privacy and Security Notice

Connect.

  • Data
  • Inspector General
  • Jobs
  • Newsroom
  • Regulations.gov
  • Subscribe
  • USA.gov
  • White House

Ask.

  • Contact EPA
  • EPA Disclaimers
  • Hotlines
  • FOIA Requests
  • Frequent Questions
  • Site Feedback

Follow.