Exhibit_E-DataExchangeAgreement.docx

DOCX document 132 KB Posted

Attached to
Teleradiology Service, HHCC Federal contract opportunity
Solicitation number
16-247-SOL-00013
Issued by
Department of Health and Human Services Indian Health Service

About this file

Exhibit E-Data Exchange Agreement (DEA) Template

View the file

Other files for this federal contract opportunity

Other files attached to Teleradiology Service, HHCC, newest first.
File Type Posted
Exhibit_A-SF1449_(revised).pdf PDF
Amendment_0002.pdf PDF
Amendment_0001.pdf PDF
Exhibit_A-SF1449.pdf PDF
Exhibit_D-Bus._Partner_Interconnection_Security_Agreement.doc DOC document
Exhibit_B-Wage_Determination.docx DOCX document
Exhibit_C-Tax_Exemption_Letter_2015.pdf PDF
SOW_12.01.15.docx DOCX document
Exhibit_F-IHS_Rules_of_Behavior.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Indian Health Service Data Exchange Agreement <<Insert Area/Facility>> and <<Partner Organization>> DIS-Template-13-02 <<Month Year>> Controlled Unclassified Information

CONTROLLED UNCLASSIFIED INFORMATION

Indian Health Service <<Month Year>> This information is intended for IHS use only. Disclosure may cause harm to IHS. Access is provided by request only and is not available via the organization's Intranet. This document contains information that may be exempt from public release under the Freedom of Information Act (FOIA) (5 U.S.C. 552).

For Official Use Only ii Template Last Revised: 09/2013

CONTROLLED UNCLASSIFIED INFORMATION

DOCUMENT INFORMATION

SUPERSEDES

Data Exchange Agreement Template 09-02, March 2009 Data Exchange Agreement Template 10-02, May 2010

Contents

1.0Purpose1
2.0Authority1
3.0Statement of Requirements and Systems Description1
4.0System Security2
4.1.General Information and Data Description2
4.2.Information Security Categorization3
4.3.User Community4
4.4.Information Security Controls4
4.5.Data Exchange Parameters4
4.6.Incident Response and Reporting5
4.7.Audit Trail Responsibilities5
4.8.Training and Awareness6
4.9.Disasters and Other Contingencies6
4.10.Commitment to Protect Personally Identifiable Information (PII) and PHI6
4.11.Personnel Changes7
4.12.New Connections for Data Exchange7
5.0Policies7
6.0Federal Employees8
7.0Governing Law and Severability8
8.0Compliance and Enforcement8
9.0Appendix A: Area/Site Connections9
10.0Appendix B: Signatures10
11.0Appendix C: Information Security POCs11
12.0Appendix D: Data Flow Diagram(s)12
13.0Appendix E: Annual Reviews13
13.1.Second-Year Review13
13.2.Third-Year Review14
14.0Appendix F: References15
15.0Appendix G: IHS Incident Reporting Form16
16.0Glossary18

Purpose The purpose of this Data Exchange Agreement (DEA) is to define procedures of reciprocal cooperation and coordination between the Indian Health Service (IHS), an agency of the United States Department of Health and Human Services (HHS), and <<Partner Organization>> to identify and implement information security safeguards and responsibilities required for the establishment of a data exchange between IHS and <<Partner Organization>>.

Data exchange use means the sharing, employment, application, utilization, examination, or analysis of IHS data (for example, financial, protected health information[footnoteRef:1] [PHI], and records). [1: Protected health information is defined by 45 CFR 160.103 as “individually identifiable health information that is transmitted or maintained in any form or medium, including electronic information.”]

Authority IHS is responsible for implementing and administering an information security program, including this DEA, to protect its information resources and sensitive information[footnoteRef:2] in compliance with applicable public laws, federal regulations, and executive orders, including but not limited to the Federal Information Security Management Act of 2002 (FISMA); the Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, dated November 28, 2000; the Health Insurance Portability and Accountability Act of 1996 (HIPAA); the Health Information Technology for Economic and Clinical Health Act (HITECH); and OMB Memorandum 09-29 FY 2009, Reporting Instructions for FISMA and Agency Privacy Management. IHS will comply with the security standards required by Federal Acquisition Regulation (FAR) clause 52.239-1, Privacy or Security Safeguards. [2: Sensitive information is defined as any Personally Identifiable Information or PHI that contains two or more elements of information identifiable with an individual (e.g., name, Social Security number, phone number, home address, etc.). This information has a degree of confidentiality such that its loss, misuse, unauthorized access, or modification could compromise the element of confidentiality and thereby adversely affect national health interests, the conduct of IHS programs, or the privacy of individuals entitled under HIPAA.]

Statement of Requirements and Systems Description This DEA governs the relationship between IHS and <<Partner Organization>> regarding <<Partner Organization>>’s use of IHS information and data.

A description of the method of data access or transfer will be provided in this section. The requestor and its agents will establish specific safeguards to ensure the confidentiality and security of individually identifiable records or record information. If encrypted identifiable information is transferred electronically through means such as the Internet, then said transmissions will be consistent with the rules and standards dictated by federal statutory requirements regarding the electronic transmission of identifiable information. In no case will sensitive information be transmitted electronically without the use of FIPS 140-2 compliant encryption methods.

<<Document the formal requirements for the transfer and use of sensitive data exchange. Explain the rationale for the data exchange. Enter a brief statement justifying the data exchange. Within the information presented, include the following information:

The agency name or organization that initiated the requirement. If the requirement is generated by a higher-level agency or organization, indicate the name of the organization and the individual, if appropriate, who requested the DEA and the reason.

The justification for transferring or obtaining the data, including the benefits derived.

The technical details of the data exchange (for example, FTP, HTTP/HTTPS, automatic, or manual).

The names of the systems transmitting and/or receiving data.>> System Security <<Security and Technical Points of Contact (POCs) will provide the following information. If any item below is deemed not applicable, a statement to that effect will be made in the DEA in lieu of eliminating that item from the DEA. >> General Information and Data Description <<Describe, in general terms, the nature of the data that will be exchanged. Be sure to indicate whether <<Partner Organization>> will create, receive, view, or otherwise have access to IHS PHI.>> <<Describe in detail each element of information and/or data that will be made available, exchanged, or passed by the systems.>> Information Security Categorization Determine the categorization level of the information that will be handled through the data exchange, according to FIPS-199.

☐ LOW The potential impact is LOW if:

The loss of confidentiality, integrity, or availability could be expected to have a limited adverse effect[footnoteRef:3] on organizational operations, organizational assets, or individuals. [3: Adverse effects to individuals may include, but are not limited to, the loss of the privacy to which individuals are entitled under law.]

AMPLIFICATION: A limited adverse effect means the loss of confidentiality, integrity, or availability might, for example, (i) cause a degradation in mission capability to an extent and duration that the organization remains able to perform its primary functions, but the effectiveness of its functions is noticeably reduced; (ii) result in minor damage to organizational assets; (iii) result in minor financial loss; or (iv) result in minor harm to individuals.

☐ MODERATE The potential impact is MODERATE if:

The loss of confidentiality, integrity, or availability could be expected to have a serious adverse effect on organizational operations, organizational assets, or individuals.

AMPLIFICATION: A serious adverse effect means the loss of confidentiality, integrity, or availability might, for example, (i) cause a significant degradation in mission capability to an extent and duration that the organization remains able to perform its primary functions, but the effectiveness of its functions is significantly reduced; (ii) result in significant damage to organizational assets; (iii) result in significant financial loss; or (iv) result in significant harm to individuals that does not involve loss of life or serious or life-threatening injuries.

☐ HIGH The potential impact is HIGH if:

The loss of confidentiality, integrity, or availability could be expected to have a severe or catastrophic adverse effect on organizational operations, organizational assets, or individuals.

AMPLIFICATION: A severe or catastrophic adverse effect means the loss of confidentiality, integrity, or availability might, for example, (i) cause a severe degradation in or loss of mission capability to an extent and duration that the organization is not able to perform one or more of its primary functions; (ii) result in major damage to organizational assets; (iii) result in major financial loss; or (iv) result in severe or catastrophic harm to individuals, involving loss of life or serious or life-threatening injuries.

User Community User Community <<Describe the user community that will have access to the information under the DEA.>> <<Partner Organization>> Responsibilities <<Partner Organization>> will ensure that all employees, contractors, and other authorized users with access to IHS’s information will release data to authorized persons only.

Information Security Controls <<Partner Organization>> Responsibilities <<Partner Organization>> will ensure that information used, stored, or transmitted is protected commensurate with the risk and magnitude of the harm that could result from the unauthorized access, use, disclosure, disruption, modification, or destruction of the information. FIPS-200 and associated National Institute of Standards and Technology (NIST) Special Publications, including NIST Special Publication 800-53, will be used to determine required controls according to the information categorization defined in Section 4.2. FIPS 140-2 validated cryptographic modules will be used when such controls are required.

Data Exchange Parameters <<Partner Organization>> Responsibilities Data Security: <<Partner Organization>> agrees to store printed or imaged IHS data in a locked filing cabinet within a restricted area that is accessible only to individuals authorized pursuant to this agreement for purposes of data matching, the data exchange process, or coordination of services related to this agreement.

Electronic data will be restricted to individuals authorized pursuant to this agreement. Authorized individuals must only access electronic data using appropriate security measures such as a password-protected data security system or least privilege access.

Data Destruction: <<Partner Organization>> agrees that when the intended purpose of the data has been fulfilled, it will dispose of the information using any or a combination of the following destruction methods: (i) removing (that is, scrubbing or purging) all electronic files from hard drives or any other storage media that contain IHS information or (ii) shredding or burning any hard copies of IHS information such that the resulting residue prevents any recovery of the data.

Mutual Responsibilities Use of Information: <<Partner Organization>> and IHS agree that the information received under this agreement will not be used to the detriment of any individual nor for any purpose other than those stated in this agreement.

Disclosure of Data: <<Partner Organization>> and IHS agree not to release or disclose information to any third party not covered by this agreement unless written permission is provided by the data owner and redisclosure is not prohibited under applicable law.

Incident Response and Reporting <<Partner Organization>> Responsibilities <<Partner Organization>> must (i) establish an operational incident-handling capability for <<Partner Organization>> systems processing, transmitting, or accessing IHS information that includes adequate preparation, detection, analysis, containment, recovery, and user response activities; and (ii) track, document, and report incidents[footnoteRef:4] to appropriate organizational officials and/or authorities. [4: Incident is defined by NIST SP 800-61 as “a violation or imminent threat of violation of computer security policies, acceptable use policies, or standard security practices.” ]

Mutual Responsibilities Both parties will:

Handle and report all security incidents within their networks or subnets within the scope of this DEA that could impact the other party as part of this interconnection, which may include a data exchange or direct LAN-to-LAN connections.

Submit notification of confirmed incidents within 30 minutes to the IHS Incident Response Team (IRT) at IRT@ihs.gov. If the incident occurs after business hours, contact the IHS Help Desk at 1-888-830-7280 or the IHS NOSC at 702-562-8201 The IHS Incident Reporting Form is available in Appendix G.

Notify the IHS IRT and/or the IHS Help Desk within 30 minutes of discovery for any confirmed breach[footnoteRef:5] of IHS PHI, including unauthorized use or disclosure. [5: Breach is defined by HITECH, Section 13400, as suspected or confirmed “unauthorized acquisition, access, use, or disclosure of Protected Health Information [or Personally Identifiable Information] which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information.”]

The IHS IRT will assist IHS and its partners with all incidents and breaches of PHI.

Notify the appropriate ISSO of confirmed incidents as soon as possible.

Proper reporting of incidents and breaches allows each party to take steps to determine if its network is at risk or has been compromised and thereby take appropriate security precautions.

Audit Trail Responsibilities <<Partner Organization>> Responsibilities <<Partner Organization>> must (i) create, protect, and retain information system audit records to the extent needed to enable the monitoring, analysis, investigation, and reporting of unlawful, unauthorized, or inappropriate information system activity and (ii) ensure that the actions of individual information system users can be uniquely traced to those users so they can be held accountable for inappropriate actions.

<<Partner Organization>> will audit Internet Protocol (IP) addresses, ports and protocols used, dates and times of events, successes and failures of access attempts, and security actions taken by system administrators or security officers.

Audit logs will be retained for a minimum of six months.

Training and Awareness <<Partner Organization>> Responsibilities <<Partner Organization>> must (i) ensure that managers and users of organizational information systems with access to IHS information are made aware of the security risks associated with their activities and of the applicable laws, executive orders, directives, policies, standards, instructions, regulations, or procedures related to the security of organizational information systems and (ii) ensure that organizational personnel are adequately trained to carry out their assigned information security-related duties and responsibilities.

Disasters and Other Contingencies <<Partner Organization>> Responsibilities <<Partner Organization>> must establish, maintain, and effectively implement plans for emergency response, backup operations, and post-disaster recovery for organizational information systems to ensure the availability of critical information resources and continuity of operations in emergency situations.

<<Partner Organization>>’s POC will immediately notify IHS’s security POC by telephone or email in the event of a disaster or other contingency that disrupts normal operations.

Commitment to Protect Personally Identifiable Information[footnoteRef:6] (PII) and PHI [6: Personally identifiable information is defined by OMB Memorandum 06-19 as, “Any information about an individual maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and information which can be used to distinguish or trace an individual's identity, such as their name, SSN, date and place of birth, mother’s maiden name, biometric records, etc., including any other personal information which is linked or linkable to an individual.”]

<<Partner Organization>> Responsibilities <<Partner Organization>> will ensure that its employees, contractors, and other authorized users with access to IHS information do not release, publish, or disclose PII or PHI to unauthorized personnel, and protect such information in accordance with any applicable laws and regulations governing the adequate safeguarding of agency information, including but not limited to laws cited in Section 2, Appendix D, and the following:

HIPAA,

FISMA,

The Paperwork Reduction Act of 1978, Public Law 104-13, as amended, and The Privacy Act of 1974, Public Law 93-579, as amended.

<<Partner Organization>> will not publish or disclose in any manner, without the written consent of the IHS Chief Information Security Officer, the details of any safeguards either designed or developed by the <<Partner Organization>> under this DEA or otherwise provided by the government.

To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of government data, <<Partner Organization>> will afford the government access to <<Partner Organization>>’s facilities, installations, technical capabilities, operations, documentation, records, and databases that pertain to this DEA.

Personnel Changes <<Partner Organization>> Responsibilities <<Partner Organization>> will provide immediate notification of the separation or long-term absence of the respective network owner or technical lead.

<<Partner Organization>> will provide immediate notification of any changes in Information System Security Officer (ISSO) or POC information.

New Connections for Data Exchange New data exchange connections between IHS and <<Partner Organization>> are prohibited unless expressly agreed upon in a written modification or addendum to this DEA signed by both parties.

Policies In addition to any policies and practices referred to in this DEA, <<Partner Organization>> and its employees, contractors, and other authorized users with access to IHS’s network, systems, and information will comply with all IHS and HHS information security policies and practices. Furthermore, <<Partner Organization>> will comply with all other federal information security policies and practices applicable to <<Partner Organization>> due to its interconnection with IHS’s network, systems, or data.

Some IHS and HHS information security policies and practices can be found online via the following links:

IHS Manual, Part 8, Chapter 12 – Information Technology Security HHS Cybersecurity Program website IHS Division of Information Security website More references are available in Appendix F.

Please contact the Area ISSO, Site Manager or HQ_OITSecurity@ihs.gov to obtain electronic copies of IHS policies and procedures relevant to this DEA.

Federal Employees Nothing in this DEA will be construed to permit any federal employee to operate contrary to any applicable laws, policies, and guidelines, nor will anything in this DEA authorize or obligate federal employees to operate outside the scope of their employment.

Governing Law and Severability This DEA will be governed and construed in accordance with United States federal law. In the event of a conflict between the DEA and applicable federal law, federal law will prevail. Furthermore, nothing in this DEA will be construed to authorize <<Partner Organization>> to act outside of the scope of any federal law. If any term or condition of this DEA becomes invalid or unenforceable, it will in no way affect the validity or enforceability of any other terms or provisions contained herein.

Compliance and Enforcement <<Partner Organization>> will comply with all provisions cited within this DEA. If IHS determines that data integrity or confidentiality are at risk due to noncompliance on the part of the <<Partner Organization>>, IHS will immediately notify the <<Partner Organization>> Information Security Officer, who will have 30 days to take necessary corrective action. IHS will conduct a subsequent review of the security posture to ensure full compliance with the provisions of this DEA. If IHS determines that <<Partner Organization>> has not taken appropriate steps to remediate any cited security vulnerabilities, IHS will have the right to temporarily or permanently cease the sharing of data between the two organizations.

Appendix A: Area/Site Connections

IHS Area/Site Interconnected
Date Connected
Currently Connected?

Appendix B: Signatures Both parties agree to work together to ensure the joint security of the connected networks and the data they store, process, and transmit, as specified in this DEA. Each party certifies that its respective network is designed, managed, and operated in compliance with all relevant federal laws, regulations, and policies.

We agree to the terms and conditions of this DEA.

IHS Management POC <<Partner Organization>> Management POC

_______________________________________________________________
(Name)(Name)
_______________________________________________________________
(Signature) (Date)(Signature) (Date)

HQ/Area ISSO <<Partner Organization>> Information Security POC

_______________________________________________________________
(Name)(Name)
_______________________________________________________________
(Signature) (Date)(Signature) (Date)

Appendix C: Information Security POCs <<Partner Organization>> Responsibilities <<Partner Organization>> will designate an information security Point of Contact (POC), who will communicate all information security issues involving <<Partner Organization>> to the IHS via the IHS Security POC. The <<Partner Organization>> POC will be the <<Partner Organization>> ISSO or another information security official who will be responsible for implementing and managing <<Partner Organization>>’s information security program and ensuring that <<Partner Organization>>’s information security controls meet or exceed IHS requirements.

IHS Security POC:

Address:

Work Phone:

Fax:

Email:

24x7 Contact Number:

IHS Technical POC:

Address:

Work Phone:

Fax:

Email:

<<Partner Organization>> Security POC:

Title:

Address:

Work Phone:

Fax:

Email:

24x7 Contact Number:

<<Partner Organization>> Technical POC:

Title:

Address:

Work Phone:

Fax:

Email:

Appendix D: Data Flow Diagram(s)

Appendix E: Annual Reviews This data exchange agreement is valid for three years, but it must be reviewed each year to ensure appropriate security measures remain in place and to document any relevant changes.

Second-Year Review Both parties have reviewed this agreement and reaffirm that the information is still current unless otherwise noted in the comments section below.

We reaffirm the terms and conditions of this Data Exchange Agreement.

Comments: <<Document any relevant changes to this agreement.>> HQ/Area ISSO <<Partner Organization>> Information Security POC

_______________________________________________________________
(Name)(Name)
_______________________________________________________________
(Signature) (Date)(Signature) (Date)

Third-Year Review Both parties have reviewed this agreement and reaffirm that the information is still current unless otherwise noted in the comments section below.

We reaffirm the terms and conditions of this Data Exchange Agreement.

Comments: <<Document any relevant changes to this agreement.>> HQ/Area ISSO <<Partner Organization>> Information Security POC

_______________________________________________________________
(Name)(Name)
_______________________________________________________________
(Signature) (Date)(Signature) (Date)

Appendix F: References This DEA was developed in accordance with, but not limited to, the following laws, policies, and regulations:

Indian Health Manual Part 8, Chapter 12 Indian Health Service Information Security Program Standard Operating Procedures HHS Information Security Policies & Procedures Health Information Technology for Economic and Clinical Health Act (HITECH) of 2009 Federal Information Security Management Act of 2002 (FISMA) Office of Management and Budget (OMB) Memoranda

· 07-16 Safeguarding Against and Responding to the Breach of Personally Identifiable Information

· 09-29 FY 2009 Reporting Instructions for FISMA and Agency Privacy Management National Institute of Standards and Technology (NIST)

· Federal Information Processing Standards (FIPS) Publications

· Special Publications (SPs)

· Draft Publications Federal Continuity Directive (FCD), FCD 1, Federal Executive Branch Continuity of Operations, November 6, 2007.

Presidential Decision Directives (PDDs)

· PDD 67, Enduring Constitutional Government and Continuity of Government Operations, October 21, 1998

· Homeland Security Presidential Directive/HSPD-7, Critical Infrastructure Identification, Prioritization, and Protection, December 17, 2003 All relevant Public Laws.

Appendix G: IHS Incident Reporting Form Important: Initial notification must be exclusively made to the IHS Incident Response Team (IRT) no later than 30 minutes from discovery. All incidents must also have a resolution completed.

Contact the IHS IRT: Email: IRT@ihs.gov; Business Hours: (505) 750-3302, (505) 386-0223, or (505) 750-1845; After Hours (Help Desk): (888) 830-7280 Check One: ☐Incident Notification ☐Update ☐Resolution

IR Primary Handler:

Does the incident involve Personally Identifiable Information (PII)?

☐Yes ☐No (if yes, complete PII box) Key Information Date/Time of Incident Discovery: Date/Time Incident Occurred:

Facility name:

Discoverer of incident:

Contact person and contact information:

Alternate contact and contact information:

<If equipment was lost/stolen, list the government barcode number(s) for the stolen equipment> <Describe the roles of the people involved, be it contractors, government employees, etc.> <Number of individuals impacted/estimated to be impacted> <List people to keep notified of incident and people who should NOT be notified>

Incident Summary <High-level summary of incident, elaborating on key information above.>

Detailed Incident Description <Detailed description of incident. Please include time stamps.>

Incident Mitigation <Detailed description of steps taken with time stamps.>

<Detailed description of follow-up actions to be taken.>

Personally Identifiable Information (PII) <What type of PII>

<Who owned the PII>

<Number of individuals impacted/estimated to be impacted>

Glossary See the online glossary on the IHS OIT/Security web page.

image1.png image2.jpeg

File details come from the government source that posted it. Updated .