2026-15428NoticeWallet

Privacy Act of 1974; System of Records

Published Date: 7/30/2026

Notice

Summary

Pursuant to the provisions of the Privacy Act of 1974, as amended, the Department of Housing and Urban Development (HUD), Office of Chief Information Security Officer (OCISO) is issuing public notice of its intent to create a new system of record titled Enterprise Identity and Credential Access Management (EICAM). The purpose of EICAM is to standardize user access controls, which provides support for users through self-service functions, and ensure only approved users may access HUD systems and data across the HUD enterprise. EICAM more efficiently reinforces the rules and controls governing the collection, maintenance, use, and sharing of information.

Analyzed Economic Effects

6 provisions identified: 2 benefits, 0 costs, 4 mixed.

HUD centralizes wide-ranging personal data

HUD will create the Enterprise Identity, Credential, and Access Management (EICAM) system that will collect and maintain many kinds of personal information — including full names, unique user identifiers, dates and places of birth, gender, mother's maiden name, contact details, photographs, race/ethnicity, driver’s license or passport details, employment information, training records, login attempts, IP addresses, and usage logs — for people issued credentials such as employees, contractors, grantees, state and local partners, public housing authorities, private partners, lenders, tenants, and program beneficiaries.

HUD will avoid storing Social Security Numbers

EICAM will use unique identifiers (for example Okta universal directory identifiers) to manage identities and 'eliminate the need to store Social Security Numbers' in the system; HUD also states SSA-provided PII will not be shared with EICAM.

Data stored and processed in FedRAMP cloud services

EICAM will store identity records in the Okta GovCloud (within AWS GovCloud) and use third-party services (including Cloudflare for routing/caching and Socure for identity proofing); processing may occur across Cloudflare’s geographically decentralized FedRAMP Moderate points of presence.

HUD may share identity records with many recipients

HUD lists routine disclosures for EICAM records to contractors, grantees, other federal/state/local agencies for investigations, the Department of Justice in litigation, the National Archives, breach-response partners, other agencies for audit/inspections, and third parties for identity proofing, fraud prevention, and studies.

New authentication requirements for HUD access

The system will require multi-factor authentication (MFA) for access to HUD on‑premises and cloud applications: Personal Identity Verification (PIV) smartcards for HUD internal users and a verification plus a One-Time Passcode (OTP) authenticator for internal or external users; Single Sign On (SSO) will also be supported.

Records retention limited to three-year baseline

EICAM records are managed under GRS 5.5: they are temporary and 'destroyed when 3 years old, or 3 years after applicable agreement expires or is cancelled,' although HUD may retain records longer if required for business use.

Personalized for You

How does this regulation affect your finances?

Personalize government policy and PRIA will tell you what this federal register document means for your household, plus every other regulation we track. PRIA reads each provision against your financial profile to show you exactly what matters to your wallet.

Key Dates

Published Date
Comments Due
Effective Date
7/30/2026
8/31/2026
9/1/2026

Department and Agencies

Department
Independent Agency
Agency
Housing and Urban Development Department
Source: View HTML

Related Federal Register Documents

Previous / Next Documents

Back to Federal Register