Comment from Sadhukhan, Maumita
Maumita SadhukhanSupportIndividual
Summary: The commenter supports the CDC's proposed continuation and revision of the Rape Prevention and Education (RPE) Program information collection. They argue that while the data collection is necessary for evaluating program effectiveness, the CDC must prioritize strict data minimization, clear confidentiality guidance, and cybersecurity reviews to protect sensitive information.
I support the Centers for Disease Control and Prevention’s proposed continuation and revision of the Rape Prevention and Education (RPE) Program information collection. The RPE Program serves an important public health function by supporting evidence-based strategies to prevent sexual violence, strengthen community prevention infrastructure, and improve understanding of effective interventions. Collecting information from funded recipients is necessary to evaluate program implementation, ensure responsible use of federal resources, and guide future prevention efforts.
However, because the RPE Program addresses a highly sensitive public health issue, I recommend that the CDC continue to prioritize privacy protections and confidentiality safeguards throughout the data collection process. Individuals and organizations involved in sexual violence prevention efforts may be handling information related to survivors, communities experiencing elevated risk, and populations that may face stigma or discrimination. Protecting privacy is essential to maintaining trust between public health agencies, funded organizations, and the communities they serve.
First, the CDC should ensure that all collected information follows strict data minimization principles. Reports should collect only the information necessary to evaluate program implementation and effectiveness while avoiding unnecessary collection of personally identifiable information or sensitive individual-level data. Whenever possible, aggregate-level reporting should be used to reduce the risk of identifying survivors or vulnerable populations.
Second, the CDC should provide clear guidance to RPE recipients regarding confidentiality standards, secure data management practices, and appropriate handling of sensitive information. This guidance should include expectations for data storage, access restrictions, encryption practices, and procedures for securely transferring information to federal systems.
Third, the CDC should consider conducting periodic reviews of data security practices associated with the RPE Program’s reporting systems. As technology evolves, continued assessment of cybersecurity protections will be important to prevent unauthorized access, disclosure, or misuse of sensitive information.
Finally, the CDC should incorporate privacy considerations into technical assistance and training provided to RPE recipients. Smaller organizations and community-based partners may have limited administrative resources, and providing standardized privacy resources, templates, and training materials would help ensure consistent protections across all participating organizations.