10.3 Personally Identifiable Information (PII)
Key Takeaways
- Protection of sensitive public data—including Personally Identifiable Information (PII), Federal Tax Information (IRC § 6103), and health data (HIPAA)—requires layered technical safeguards such as TLS 1.3/AES-256 encryption, phishing-resistant Multi-Factor Authentication (MFA), role-based access control (RBAC), and rapid incident response (NIST SP 800-61).
- The Federal Information Security Modernization Act (FISMA) requires federal agencies to operate risk-based information-security programs, with ongoing monitoring and independent annual evaluation; nonfederal governments follow the security authorities applicable to them.
- E-Government transforms public administration by delivering critical citizen and business services through secure, accessible digital channels, including automated tax filing, license renewals, and direct benefit disbursements.
1. Personally Identifiable Information (PII)
PII is defined by OMB as information that can be used to distinguish or trace an individual's identity (such as name, Social Security Number, date of birth, biometric records), either alone or when combined with other personal or identifying information. Protections are mandated by the Privacy Act of 1974 and OMB Circular A-130. Agencies must conduct Privacy Impact Assessments (PIAs) before developing or procuring systems that process PII.
2. Federal Tax Information (FTI) & IRC § 6103
Federal Tax Information (FTI) is governed by the strictest confidentiality mandates in American law under Internal Revenue Code § 6103. FTI consists of any return or return information received from the IRS. State revenue departments, social service agencies, and municipal child support agencies that receive FTI must implement rigorous physical, electronic, and administrative safeguards detailed in IRS Publication 1075 (Tax Information Security Guidelines).
Federal law distinguishes the offenses. A willful unauthorized disclosure under 26 U.S.C. § 7213 is a felony punishable by a fine of up to $5,000, imprisonment of up to five years, and dismissal from federal office or employment. A willful unauthorized inspection under § 7213A is a misdemeanor punishable by a fine of up to $1,000, imprisonment of up to one year, and dismissal. Civil damages may also apply under § 7431.
3. Protected Health Information (PHI) & HIPAA
Government agencies administering Medicaid, public health programs, workers' compensation, or municipal employee self-insured health plans must comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security and Privacy Rules. HIPAA mandates technical safeguards (encryption, audit logging, access controls) to prevent unauthorized disclosure of individually identifiable health data.
Comparative Analysis: Public Sector Data Governance Frameworks
| Regulated Data Type | Governing Legal Authority | Core Mandatory Safeguards | Penalties for Unauthorized Disclosure |
|---|---|---|---|
| Personally Identifiable Information (PII) | Privacy Act of 1974; OMB Circular A-130; E-Gov Act of 2002. | Privacy Impact Assessments (PIAs); System of Records Notices (SORNs); encryption; least privilege. | Civil lawsuits for actual damages; administrative disciplinary action; termination. |
| Federal Tax Information (FTI) | Internal Revenue Code § 6103; IRS Publication 1075. | Dedicated secure network zones; FIPS-validated encryption; background checks; strict audit trails. | Federal felony: up to 5 years prison, $5,000 fine, mandatory job loss; civil damages of $1,000 per violation. |
| Protected Health Information (PHI) | HIPAA Security & Privacy Rules (45 C.F.R. Parts 160 & 164). | Administrative safeguards; role-based access; end-to-end encryption; business associate agreements. | Multi-tier civil monetary penalties up to $2 million annually; federal criminal penalties for willful fraud. |
| Open Financial Data | FFATA of 2006; DATA Act of 2014; state open records laws. | Machine-readable standardized formats; automated PII and bank account masking prior to publication. | Administrative sanctions; mandatory remediation of portal leaks; public retraction. |
Technical Defenses in Public Financial Systems
To maintain compliance with FISMA, NIST SP 800-53, and statutory data mandates, public financial managers must enforce rigorous technical controls across enterprise financial platforms:
1. Cryptographic Standards: In Transit and At Rest
All sensitive financial information and credentials must be cryptographically protected:
- Data in Transit: When financial data travels over internal networks or the public Internet (such as vendor portals or banking interfaces), it must be protected using Transport Layer Security (TLS 1.3) or secure IPSec VPN tunnels, preventing interception, packet sniffing, or man-in-the-middle attacks.
- Data at Rest: When stored in databases, storage area networks (SAN), application servers, or backup media, data must be encrypted using Advanced Encryption Standard (AES) with 256-bit keys (AES-256) running on cryptographic modules validated under FIPS 140-3.
2. Multi-Factor Authentication (MFA) and Zero Trust Architecture
Following Presidential Executive Order 14028 (Improving the Nation's Cybersecurity), federal agencies and their grant-funded partners must implement modern Zero Trust Architectures. The foundation of this defense is phishing-resistant Multi-Factor Authentication (MFA). Traditional passwords and SMS-based verification codes are prohibited for administrative and financial system access; agencies must utilize hardware tokens, FIDO2/WebAuthn security keys, or Personal Identity Verification (PIV) / Common Access Card (CAC) smart cards.
3. Role-Based Access Control (RBAC) and Separation of Duties (SoD)
In Enterprise Resource Planning (ERP) and core financial accounting systems, access must be governed by the principle of least privilege—granting an employee only those system permissions strictly necessary to perform their official duties. Furthermore, systems must programmatically enforce Separation of Duties (SoD) to prevent internal fraud:
- The user who sets up a new vendor in the vendor master file cannot approve purchase orders or authorize disbursements to that vendor.
- The employee who enters a manual journal entry cannot post or approve that entry.
- Payroll administrators cannot modify their own pay rates or direct deposit banking details.
4. Audit Logging and Immutable Traceability
Under NIST SP 800-53 (Control Family AU), financial systems must generate comprehensive, tamper-evident audit logs capturing every user login, transaction creation, record modification, data export, and permission change. These logs must be mirrored in real time to immutable, write-once storage and monitored by automated Security Information and Event Management (SIEM) engines to detect anomalous behavior.
Incident Handling and Cyber Resilience (NIST SP 800-61)
Despite sophisticated perimeter defenses, public financial systems face constant threat of compromise. Agencies must maintain formal incident response capabilities following NIST SP 800-61 Rev. 2 (Computer Security Incident Handling Guide).
┌─────────────────────────────────────────────────────────────┐
│ 1. PREPARATION │
│ Policies, Incident Response Team, Forensic Tools, Training │
└──────────────────────────────┬──────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ 2. DETECTION AND ANALYSIS │
│ SIEM Alerts, Anomaly Detection, Triage, Scope Assessment │
└──────────────────────────────┬──────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ 3. CONTAINMENT, ERADICATION & RECOVERY │
│ Network Isolation, Threat Removal, Clean System Restore │
└──────────────────────────────┬──────────────────────────────┘
▼
┌─────────────────────────────────────────────────────────────┐
│ 4. POST-INCIDENT ACTIVITY │
│ Lessons Learned, Forensic Reporting, Control Hardening │
└─────────────────────────────────────────────────────────────┘
Mandatory Incident Notification Timelines
When a major cybersecurity incident occurs, public financial managers must immediately coordinate with technical teams to fulfill statutory reporting obligations:
- Federal Agencies: Under OMB guidance and FISMA, federal agencies must report major cyber incidents to the Cybersecurity and Infrastructure Security Agency (CISA) / US-CERT within one hour of confirmation.
- State and Local Entities: Must adhere to state data breach notification laws, which typically mandate formal notice to affected individuals, state Attorneys General, and financial credit agencies within strict time horizons (e.g., 30 to 45 days, or immediately if financial accounts are breached).
- FTI and HIPAA Breaches: Incidents compromising FTI must be reported immediately to the Treasury Inspector General for Tax Administration (TIGTA) and the IRS Office of Safeguards within 24 hours. HIPAA breaches affecting 500 or more individuals require mandatory notification to the Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and prominent media outlets within 60 days.
Practical Public Finance Scenario: Ransomware Attack and Exfiltration of State Disbursement Data
To illustrate the integration of e-government systems, cybersecurity standards, and public sector ethics, consider the following practical scenario:
Scenario: Elena Rostova, CGFM, is the Comptroller of the State Department of Revenue and Financial Administration. On a Thursday morning, four business days before the state's scheduled monthly $320 million municipal aid and vendor payment disbursement cycle, the state's Security Operations Center detects an active intrusion. A foreign ransomware syndicate has compromised the state's core financial disbursement server through a compromised third-party contractor credential lacking phishing-resistant MFA.
The attackers have encrypted the general ledger databases and exfiltrated 450 gigabytes of unencrypted staging files containing municipal vendor banking details, routing numbers, and state employee PII. The attackers transmit a ransom note demanding $15 million in cryptocurrency within 72 hours, threatening to publish the sensitive financial data and permanently destroy the decryption keys if the state fails to pay.
Professional Financial Analysis
- Immediate Execution of NIST SP 800-61 Incident Protocol:
- Containment: Elena must immediately authorize the physical and logical disconnection of the affected ERP servers from the state network to prevent the ransomware from spreading to unaffected state agency clusters.
- Forensic Triage: Engage internal incident response teams and external digital forensic investigators to identify the exact point of entry, preserve server system logs for evidentiary purposes, and assess the full perimeter of data exfiltration.
- Statutory and Regulatory Notification Mandates:
- Because the breach involves vendor banking records and employee PII, Elena must trigger formal breach notifications under state data breach statutes, notifying affected vendors and employees.
- If the compromised database contains Federal Tax Information (FTI), Elena is legally compelled under IRS Publication 1075 to notify the Treasury Inspector General for Tax Administration (TIGTA) and the IRS within 24 hours.
- Coordinate immediate incident reporting to the FBI Cyber Division and CISA.
- Fiduciary Assessment of Ransom Demands and System Recovery:
- As a government entity, paying a ransom raises severe legal and ethical barriers. Federal guidance from the Department of the Treasury's Office of Foreign Assets Control (OFAC) warns that paying ransoms to sanctioned cybercriminal syndicates may violate federal sanctions laws. Furthermore, paying a ransom with public funds creates an unacceptable fiduciary precedent and provides no guarantee that exfiltrated records will not be published or that decryption keys will function.
- Elena must direct the IT and disaster recovery teams to restore the general ledger and disbursement engines from immutable, air-gapped, offline backups verified prior to the breach date.
- Post-Incident Corrective Actions and Control Hardening:
- In compliance with NIST SP 800-53 and Executive Order 14028, mandate immediate implementation of phishing-resistant hardware MFA (FIDO2/PIV) across all internal and contractor administrative accounts.
- Enforce database-level encryption at rest (AES-256) for all staging and transactional tables, ensuring that even if files are exfiltrated in the future, the data remains cryptographically unreadable without hardware-protected encryption keys.
What are the legal requirements and ramifications governing state and local government employees who receive Federal Tax Information (FTI) pursuant to Internal Revenue Code § 6103?