Revised_Web_Services_RFP_Released_24_May_17.docx

DOCX document 298 KB Posted

Attached to
Web Support Services Federal contract opportunity
Solicitation number
17-236-SOL-00007
Issued by
Department of Health and Human Services Indian Health Service

About this file

Revised RFP

View the file

Other files for this federal contract opportunity

Other files attached to Web Support Services, newest first.
File Type Posted
Revised_Web_Services_RFP_Released_Amendment0004.docx DOCX document
Web_Support_Questions_and_Responses_Released_14_June_17.docx DOCX document
Revised_Web_Services_RFP_Released_Amendment0003.docx DOCX document
Revised_Web_Support_Combined_Synopsis_24_May_17.docx DOCX document
Web_Support_Combined_Synopsis.docx DOCX document
QASP_Web_Services.docx DOCX document
Web_Services_RFP_Released_23_May_17.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Section A Indian Health Service Request for Proposal for

Office Information Technology (OIT) Web Support Services

(RFP) 17-236-SOL-00007

You are invited to submit a proposal in accordance with the requirements of the following Solicitation.

Proposals must be received by the Government no later than the local time on the Due Date stated in the table below.

Issue Date:
05/23/2017
Due Date:
06/20/2017
Time:
4:00 p.m., EST
Points of Contact:
Wendy McNorial

(301) 945-3145 wendy.mcnorial@ihs.gov

SECTION B – PRODUCTS OR SERVICES AND PRICES/COSTS

B.1. OVERVIEW

The Contractor shall provide the commercial services described in Section C, Description/ Specifications/Performance Work Statement (PWS). Except as otherwise specified in the contract, the Contractor shall furnish the necessary personnel, equipment, materials, services, and otherwise do all things necessary for the performance of the work set forth herein.

B.2. CONTRACT TYPE

This is a Labor Hour contract.

B.3. CONTRACT PRICING

The Indian Health Service (IHS) intends to issue one contract containing Fixed-Price burdened labor rates per the labor categories listed below. This requirement is being solicited among all qualified Indian Small Business Economic Enterprise (ISBEE) contractors. You are invited to submit a written proposal utilizing the below Schedule of Prices for the services specified in Section C, under Request for Proposal (RFP) 17-236-SOL-00007.

B.4. NUMBER OF HOURS INCURRED

Contractor shall include a time sheet with each invoice showing the number of hours worked. This time sheet shall show the number of hours worked per person by labor category during the time period invoiced.

SCHEDULE OF PRICES

NOTE: The contractor shall provide a full supplementary security services that provides IHS with a professional level staff of security specialists experienced in conducting, researching, documenting and implementing information security related processes in accordance with SOW and all other terms and conditions set forth in this solicitation package. CLIN = Contract Line Item Number; PWS = Performance Work Statement.

BASE PERIOD

The Department of Health and Human Services, Indian Health Service (IHS) is procuring a labor hour type contract for Web Support Services. The support services required must satisfy the requirements described in the Performance Work Statement (PWS).

A. The Contractor shall apply fixed labor rates to the following:

Contract Role
ASB Labor Category
Proposed Rate
Hours
Price
Project Manager (Key)
Project Manager
Development Team Lead (Key)
Applications Developer (Master)
Cold Fusion Application Developer
Applications Developer (Journeyman)

Web UI/UX Developer (Key) Web Designer

SharePoint Developer Lead/ Architect (Key)
Applications Developer (Journeyman)
Web Content Editor
Web Content Analyst
Software System Analyst
Business Systems Analyst
Quality Assurance Analyst
Quality Assurance Specialist (Journeyman)
Systems Administrator
Applications Systems Analyst (Senior)
SQL Server Database Administrator
Database Specialist (Journeyman)

Total Price

OPTION PERIOD 1

B. The Contractor shall apply fixed labor rates to the following:

Contract Role
ASB Labor Category
Proposed Rate
Hours
Price
Project Manager (Key)
Project Manager
Development Team Lead (Key)
Applications Developer (Master)
Cold Fusion Application Developer
Applications Developer (Journeyman)

Web UI/UX Developer

Web Designer

SharePoint Developer Lead/ Architect (Key)
Applications Developer (Journeyman)
Web Content Editor
Web Content Analyst
Software System Analyst
Business Systems Analyst
Quality Assurance Analyst
Quality Assurance Specialist (Journeyman)
Systems Administrator
Applications Systems Analyst (Senior)
SQL Server Database Administrator
Database Specialist (Journeyman)

Total Price

OPTION PERIOD 2

C. The Contractor shall apply fixed labor rates to the following:

Contract Role
ASB Labor Category
Proposed Rate
Hours
Price
Project Manager (Key)
Project Manager
Development Team Lead (Key)
Applications Developer (Master)
Cold Fusion Application Developer
Applications Developer (Journeyman)

Web UI/UX Developer

Web Designer

SharePoint Developer Lead/ Architect (Key)
Applications Developer (Journeyman)
Web Content Editor
Web Content Analyst
Software System Analyst
Business Systems Analyst
Quality Assurance Analyst
Quality Assurance Specialist (Journeyman)
Systems Administrator
Applications Systems Analyst (Senior)
SQL Server Database Administrator
Database Specialist (Journeyman)

Total Price

OPTION PERIOD 3

D. The Contractor shall apply fixed labor rates to the following:

Contract Role
ASB Labor Category
Proposed Rate
Hours
Price
Project Manager (Key)
Project Manager
Development Team Lead (Key)
Applications Developer (Master)
Cold Fusion Application Developer
Applications Developer (Journeyman)

Web UI/UX Developer

Web Designer

SharePoint Developer Lead/ Architect (Key)
Applications Developer (Journeyman)
Web Content Editor
Web Content Analyst
Software System Analyst
Business Systems Analyst
Quality Assurance Analyst
Quality Assurance Specialist (Journeyman)
Systems Administrator
Applications Systems Analyst (Senior)
SQL Server Database Administrator
Database Specialist (Journeyman)

Total Price

OPTION PERIOD 4

E. The Contractor shall apply fixed labor rates to the following:

Contract Role
ASB Labor Category
Proposed Rate
Hours
Price
Project Manager (Key)
Project Manager
Development Team Lead (Key)
Applications Developer (Master)
Cold Fusion Application Developer
Applications Developer (Journeyman)

Web UI/UX Developer

Web Designer

SharePoint Developer Lead/ Architect (Key)
Applications Developer (Journeyman)
Web Content Editor
Web Content Analyst
Software System Analyst
Business Systems Analyst
Quality Assurance Analyst
Quality Assurance Specialist (Journeyman)
Systems Administrator
Applications Systems Analyst (Senior)
SQL Server Database Administrator
Database Specialist (Journeyman)

Total Price

Section C – Description/Specifications/Performance Work Statement

C.1 Background The Indian Health Service (IHS) is the principal Federal health care provider and health advocate for American Indian/Alaska Native people and provides a comprehensive health services delivery system for American Indians and Alaska Natives. The range of services includes traditional inpatient care, ambulatory care, preventive care, and population health delivered through a network of hospitals and clinics, and distributed through 35 states. The IHS has an ever-expanding web presence that spans across the official IHS.gov domain. IHS.gov domain includes several primary internal and external sites with several hundred topic level pages and collaborative environments as well as dozens of web applications and their respective databases. The public IHS website, www.ihs.gov, is the primary communication tool for the Indian Health Service to the public of the United States. Information disseminated through this website includes agency information, health information for clinical providers and public consumption, research, best practices, training, blogs, cross agency links, and news. Information accuracy, accessibility and usability are important to successfully fulfilling the mission of the Indian Health Service. The IHS Office of Information Technology (OIT) is supports and maintains the availability, integrity, and confidentiality of the IT systems that support the IHS mission.

This document defines the Scope of Work covering development, maintenance, documentation, technical support, deployment, and projects managed by the IHS Office of Information Technology (OIT) Division of Information Technology (DITO) Web Services team.

C.2 Scope of Requirements

C.2.1 Purpose The purpose of this contract is for website and web application development, web content management, database management, quality assurance, and support for the overall functionality of the Indian Health Service IHS.gov domain.

The IHS.gov domain currently consists of approximately 175 unique topic static websites and 80 web applications. Additionally, there is a SharePoint environment with approximately 325 hundred sites.

C.2.2. Period of Performance Period of Performance is August 1, 2017 through 31 July 2018 plus four optional 1 year renewals. Contractor operational hours based on Eastern Time, normal business hours, 8:00 AM– 5:00 PM Eastern Time, Federal Holidays excluded, with 8 hours per month of off-hour support for scheduled maintenance.

C.2.3 Primary Objectives

a. Maintain existing web applications and websites.

b. Develop, design, and test the implementation of new website development, enhancements to existing websites, web applications, web components, and content.

c. Develop and maintain web services documentation for projects and systems.

d. Maintain and manage web environment including SharePoint, LISTSERV, and web servers.

e. Ensure security compliance, accessibility, and be in accordance with all IHS and federal regulations.

f. Maintain and improve the program management of all IT Projects according to the established IHS standards and HHS Enterprise Performance Life Cycle (EPLC) standards where applicable.

C.2.4 Develop and Maintain Websites Acceptable level of quality is delivering products within a 10% variance of the agreed upon timeframe.

a. Manipulate graphics and images and optimize for website use.

b. Design websites using ColdFusion, HTML, JavaScript, jQuery, Bootstrap and CSS.

c. Develop templates for mobile, desktop and responsive design.

d. Develop graphic mockups based on user requirements.

e. Develop and maintain a standard icon library.

f. Provide user support for all website content managers.

g. Adhere to all web federal laws and regulations outlined at, http://www.digitalgov.gov/resources/checklist-of-requirements-for-federal-digital-services/ C.2.5 Develop and Maintain Web Applications

a. Develop documentation, including Systems Requirements Specifications documents and Business Requirements Documents for web applications.

b. Develop web based GUIs that comply with IHS usability and programming standards.

c. Develop web-based reports on project sponsor requirements.

d. Develop templates for mobile, desktop and responsive design.

e. Establish and maintain a pattern library for IHS.gov.

f. Manage and maintain all Web Services databases as they relate to the web applications.

g. Develop web applications according to Section 508 and Usability requirements established by the IHS, HHS, and the federal government.

h. Provide User Support for all web application users internal and external to IHS.

i. Provide application level support for all IHS.gov web servers – this includes patching, troubleshooting, and bug fixes.

j. Develop wireframes and prototypes of web applications, prior to coding, that are made available to project team via SharePoint.

k. Compile and provide information describing all database tables, indexes and formats used for each application.

l. Develop design specification documents which include system view diagrams, software prerequisites, any typical hardware or system requirements and any additional caveats or warnings.

m. Design project test plans documenting the testing process to determine how proposed changes/enhancements will be validated and meet the required business needs.

n. Develop presentation and training material for project team members.

o. Adhere to all web federal laws and regulations outlined at, http://www.digitalgov.gov/resources/checklist-of-requirements-for-federal-digital-services/ C.2.6 Content Review & Documentation

a. Review IHS.gov content for plain writing, consistent voice, readability and IHS.gov Style Guide compliance.

b. Prepare and maintain Web Services Documentation.

c. Provide training and support to IHS.gov content managers for documentation compliance needs.

d. Develop and deliver training to IHS staff requesting/requiring Section 508 documentation training.

e. Maintain a record of IHS.gov documentation compliance outlining overall compliance where deficiencies exist.

f. Review nightly logs to determine if documentation put into production that was non- compliant and how and when any issues will be addressed.

g. Develop and maintain up-to-date documentation for all information used to support the production IHS.gov environment. These documents shall be available to the COR, other IHS staff and contract staff.

C.2.7 Develop and Maintain SharePoint environment

a. Create SharePoint sites for employees within 3-5 business days of receiving the request.

b. Provide technical support for the entire SharePoint environment.

c. Migrate SharePoint sites for various versions for SharePoint.

d. Establish a standard look and feel of SharePoint sites and assist in enforcement.

e. Develop and document SharePoint enterprise policies in collaboration with Federal web managers.

f. Provide training for employees on use of SharePoint and its available features.

g. Monitor server usage and report findings monthly.

h. Provide architecture and governance guidance.

i. Work with other IHS vendor(s) for any new environment upgrades and migrations.

j. Provide guidance on setup/configuration of using cloud storage versus server storage.

k. Research, develop, and implement features and functionalities that are unavailable at this time, such as eDiscovery, workflows, and other capabilities of SharePoint 2013 and newer versions.

l. Act as the primary support role for end users.

C.2.8 Manage and Maintain Web Environment

a. Maintain operation of all IHS.gov system servers including the LISTSERV server, SharePoint servers, Web servers, and SQL servers with a service availability of 99% of the time.

b. Monitor and manage system resources, including CPU usage, disk usage, and response times to maintain operating efficiency.

c. Perform systems security administration functions, including creating user profiles and accounts and system security patches.

d. Maintain system documentation.

e. Install system wide software and allocate mass storage space, and coordinate installation and provide backup recovery.

f. Develop and monitor policies and standards for allocation related to the use of computing resources.

g. Conduct an analysis of the current web environment to determine if there are new technologies and innovative features to enhance and optimize the web environment.

C.2.9 Manage and Maintain IHS.gov Database

a. Maintain IHS.gov SQL Server environment.

b. Implement and optimize the SQL database systems that support the IHS.gov environment.

c. Conduct performance tuning of indexes and databases.

d. Review database design and integration of systems, provide backup recovery and make recommendations regarding enhancements and/or improvements.

e. Maintain security and integrity controls.

f. Formulate policies, procedures, and standards relating to database management, and monitor transaction activity and utilization.

g. Oversee the scheduling of database projects, database and transaction log backups, notifications, and database replication.

h. Review technical designs, reports, documentation, and other materials produced by staff.

i. Maintain and improve all Disaster Recovery plans to include design, configuration, testing and documentation on a yearly basis.

C.2.10 Alerts management, monitoring and reporting

a. The Contractor will be required to implement and support all routine monitoring of the web server infrastructure, critical services, and website issues.

b. The Contractor shall follow established Service Level Agreements for service level monitoring and other related alerts.

c. Notifications will be required to Federal Manager and COR for all critical service impacts and outages. Monthly reports on service availability required for all web systems and services identified.

C.2.11 Key Personnel Individuals designated as key personnel will be committed to the project for its duration and cannot be substituted or replaced without the written agreement of the Contracting Officer (CO).

Personnel shall be familiar with and have extensive knowledge and experience using industry best practices in an enterprise environment of the same or greater scope of IHS. The following are examples of potential labor categories and their individual skill requirements:

a. Project Manager - Project managers must be Project Management Professional (PMP) certified. They also must be experienced with Microsoft Project Server. Duties include supervising and coordinating with all Technical staff, supporting and managing IHS IT Projects in coordination with the Federal Managers and abiding by all Enterprise Performance Lifecycle and Capital Planning and Investment Control policies and guidelines.

Key Qualifications:

· A current Project Management Professional (PMP) certification.

· A minimum of 3 years’ experience managing IT, web development and/or web communications projects.

· A minimum of 3 years’ experience with Enterprise Performance Lifecycle and Capital Planning and Investment Control policies and guidelines.

b. Web Developer(s) - Application developers must be capable of developing and maintaining Adobe ColdFusion based web applications, providing technical documentation, coding to industry standards, and team oversight. Duties include analyzing and troubleshooting services for complex problems, recommending improvements, staying up-to-date on security vulnerabilities, new features, hardware, software, and feasibility determination. This includes knowledge of Coldfusion Server, Content Management Systems, preferably Mura, Adobe Media Server, and SQL.

Key Qualifications:

· A minimum of 5 years’ experience working in technologies Coldfusion, Javascript, JQuery, CSS, HTML, SQL, Content Management Systems, Bootstrap, and WCAG 2.0 AA conformance standards.

c. Web Front End Developer(s)/Designer(s) - Duties include using JavaScript, CSS, HTML4/5, ColdFusion, Bootstrap, Content Management Systems and provide analysis on current design trends and solutions to overall design management of IHS.gov and prototype.

Key Qualifications:

· A minimum of 3 years’ experience supporting a large website using technologies such as Coldfusion, HTML, Bootstrap, CSS, Javascript, JQuery, Content Management Systems, and WCAG 2.0 AA conformance standards.

d. SharePoint Developer(s)/Administrator(s) - SharePoint Architects and Administrators must be certified as a Microsoft Certified Solutions Expert (MCSE) in SharePoint, and Microsoft Certified Solutions Developer (MCSD). They also must be able to work with PowerShell, HTML, CSS, JavaScript, C#, and content management systems (preferably Mura). Experience with Windows Server, IIS, and SQL along with clustering, disaster recovery, virtualization, and other components in a SharePoint environment is also necessary.

Key Qualifications:

· Shall possess in-depth knowledge of migrating SharePoint environments, and experience with technologies Microsoft Server, IIS, SQL, PowerShell, HTML, CSS, Javascript, C#.

· Must be certified as a Microsoft Certified Solutions Expert (MCSE) in SharePoint, and Microsoft Certified Solutions Developer (MCSD).

C.2.12 Project Management

a. Conform to IHS Office of Information Technology Program/Project Management Processes consistent with the HHS EPLC Policy.

b. Establish Change Management Plans, Risk Management Plans, and Communications Plans documenting proposed changes, risk mitigation and communication process in resolving issues, proposed changes or web project modifications.

c. Provide project management of contracted activities including the tracking and reporting on web services projects that reflect status and variance including Earned Value Management (EVM), Cost, and Schedule.

d. Maintain a Work Breakdown Structure (WBS) describing the operational and developmental activities including key deliverables in Microsoft Project Server format.

e. Provide customer level access to weekly updated WBS, costs, EVM and schedule status and variances at both summary and detail levels.

f. Utilize IHS provided time tracking system to monitor and manage contractor hours expended to support IHS projects by project and number of hours.

g. Track EVM and compile monthly operational cost and EVM reports by project for hours spent per person on each project by internally assigned project number.

h. Provide Program support and other data or information related to Contractor activities that are required for effective management of the Investment by the Program Manager, including that required by the HHS Capital Planning and Investment Control (CPIC) and OMB Exhibit 53 and 300.

i. Provide proactive outreach support to IHS and program stakeholders to translate customer requirements into the technical solution as well as advisement to the IHS program manager regarding stakeholder perspectives and requirements.

C.2.13 Data Quality Assurance

a. Maintain and improve a quality assurance process that ensures technical requirements are established; products and services conform to established technical requirements; and satisfactory performance is achieved for contracted services.

C.2.14 Security Requirements

a. Ensure that all systems access control maintain compliance with the logical access control as specified in Homeland Security Presidential Directive 12 (HSPD-12)

b. Ensure that the system security objectives and needs are met and the appropriate level of effort for the system risk management activities is determined in accordance with FIPS Publication 199, NIST SP 800-30.

c. Ensure that the security controls needed to adequately protect the system meet the security requirements of the system and are selected in accordance with NIST SP 800-53, Federal regulations, HHS policy, and IHS IT Security Policy.

d. Verify that all selected encryption products are validated under the Cryptographic Module Validation Program to confirm compliance with FIPS 140-2 and provide a written copy of the validation documentation to the COR.

e. Maintain security processes that prevent the release, publication, or disclosure of information to unauthorized personnel, and protect such information in accordance with provisions of the following laws and any other pertinent laws and regulations governing the confidentiality of sensitive information: 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records); 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and Public Law 96-511 (Paperwork Reduction Act).

f. The Contractor/Subcontractor organization under this contract shall complete a Business Associate Agreement (BAA) per IHS and Health Insurance Portability and Accountability Act (HIPAA) requirements.

g. Ensure all identified IHS.gov web application users are assigned the appropriate level of security and report access as defined by the application owner prior to production status.

h. Collaborate with the IHS OIT Division of Information Security to facilitate initial and periodic system security assessment and authorization as well as continuous monitoring activities.

i. Resolve new risks identified by IHS, HHS, and any third party vendors. When necessary, develop Plan of Action and Milestones (POAMs) in collaboration with the IHS Office of Information Technology Division of Information Security.

j. Additionally, remediate any security flaws encountered by the HHS/Federal security-scanning tool(s).

C3. Quality Control Quality Control is the responsibility of the Contractor. The Contractor is responsible for the delivery of quality services/supplies to the Government (see FAR 52.246-1 Contractor Inspection Requirements).

C.3.1 Quality Control Program

a. The Government is committed to a highly interactive relationship between quality control by the Contractor and quality assurance by the government recipient of services. This relationship shall be achieved through an effective Prevention Based Quality Control Program dedicated to ensuring the best possible products and services to end users. The Contractor shall provide their final written Quality Control Plan (QCP) no later than (NLT) 15 days after award date and within five (5) days of any proposed changed to the COR and CO.

b. The Contractor’s quality program shall demonstrate its prevention-based outlook by meeting the objectives stated in the PWS throughout all areas of performance. The QCP shall be developed to specify the Contractor’s responsibility for management and quality control actions to meet the terms of the contract. The QCP as a minimum shall address continuous process improvement; procedures for scheduling, conducting and documentation of inspection; discrepancy identification and correction; corrective action procedures to include procedures for addressing Government discovered non-conformances; procedures for root cause analysis to identify the root cause and root cause corrective action to prevent re-occurrence of discrepancies; procedures for trend analysis; procedures for collecting and addressing customer feedback/complaints.

c. The Contractor shall provide detailed monthly status reports. This shall include any summary information used to track quality control, including any charts/graphs.

d. The Contractor’s QCP shall be incorporated into and become part of this contract after the plan has been accepted by the CO. Proposed changes made after CO acceptance shall be submitted in writing through the COR to the CO for review and acceptance prior to implementing any revision. The Contractor’s QCP shall be maintained throughout the life of the contract and shall include the Contractor’s procedures to routinely evaluate the effectiveness of the plan to ensure the Contractor is meeting the performance standards and requirements of the contract.

C.3.2 Contractor Discrepancy Report (CDR)

a. When the Contractor's performance is unsatisfactory, a CDR will be issued. The Contractor shall reply in writing within five (5) work days from the date of receipt of the CDR, giving the reasons for the unsatisfactory performance, corrective action taken, and procedures to preclude recurrence.

C.3.3 Quality Assurance

a. The COR will evaluate the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the COR must do to ensure that the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). When an observation indicates defective performance, the COR will require the Contractor or designated on-site representative to initial the observation to acknowledge the defective performance. The acknowledgement of the observation does not necessarily constitute Contractor concurrence with the observation, only that the Contractor has been made aware of the defective performance.

C.4 Phase-In/Phase-Out C.4.1 Phase-In

a. To minimize any decreases in productivity and to prevent possible negative impact on additional services, the Contractor shall have all key personnel on board, during the 30 day phase-in period. During the phase-in period, the Contractor shall become familiar with performance requirements, in order to commence full performance of services on the start of the base period of performance. The Contractor shall complete required IHS and HHS trainings, inventory and transfer GFE, obtain PIV during the phase-in period.

C.4.2 Phase-Out

a. Prior to the completion of this contract, an observation period shall occur, at which time team management personnel of the incoming Contractor may observe operations. This will allow for orderly turnover of facilities, equipment, and records and will help to ensure continuity of services. The outgoing Contractor is ultimately responsible for performing full services IAW the contract, during the phase-out period, and shall not defer any requirements for the purpose of avoiding responsibility or of transferring, such responsibility to the succeeding Contractor. The outgoing Contractor shall fully cooperate with the succeeding Contractor and the Government, so as not to interfere with their work or duties.

b. To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the outgoing Contractor shall have all personnel on board during the phase-out period. The outgoing Contractor shall be prepared to transition the work load to the newly selected Contractor during the thirty (30) day phase-out period, which will occur at the end of the period of performance of the contractual effort.

C.4.3 Phase-Out Plan

a. The incoming Contractor shall develop a phase-out plan to affect a smooth and orderly transfer of contract responsibility to a successor. The plan shall fully describe the Contractor’s approach to the following issues, at a minimum: Inventories and turn-over of government property; reconciliation of all property accounts; turn-in of excess property; data and information transfer; and any other actions required to ensure continuity of operations. The Contractor shall provide the plan to the COR thirty (30) days before the phase-out period commences.

C.5 Performance Information C.5.1 Government Furnished Equipment (GFE) The Government shall furnish at a minimum for each contractor employee a laptop computer or computer workstation, with appropriate additional hardware (e.g., mouse, keyboard, card readers, monitors) and software programs sufficient to complete assigned tasks. The Government shall provide domain access and email accounts to Contractor staff as determined by the COR to be appropriate.

C.5.2 Section 508 Compliance All Electronic and Information Technology (EIT) procured through this task, including supporting documentation, shall meet the applicable accessibility standards of 36 CFR 1194, unless an agency exception to this requirement exists. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at www.section508.gov. The Contractor shall ensure that task deliverables comply with this standard.

C.5.3 Place of Performance The work shall be performed at space provided by the contractor or via telework.

C.5.4 Security HHS-Controlled Facilities and Information Systems Security

a. To perform the work specified herein, Contractor personnel are expected to have routine (1) physical access to an HHS-controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data or information, whether in an HHS- controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

b. To gain routine physical access to an HHS facility, logical access to an HHS-controlled information system, and/or access to sensitive data or information, the Contractor and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors; Office of Management and Budget memorandum (M-05-24); and Federal Information Processing Standards Publication (FIPS PUB) Number 201; and with the personal identity verification and investigation procedures contained in the following documents:

i. HHS Information Security Program Policy.

ii. HHS Office of Security and Drug Testing, Personnel Security/Suitability Handbook, dated February 1, 2005.

iii. HHS HSPD-12 Policy Document, v. 2.0.

c. This contract/order will entail the following position sensitivity level(s): Public Trust Level 5

d. The personnel investigation procedures for Contractor personnel require that the Contractor prepare and submit background check/investigation forms based on the type of investigation required. The minimum Government investigation for a non-sensitive position is a National Agency Check and Inquiries (NACI) with fingerprinting. More restricted positions – i.e., those above non-sensitive, require more extensive documentation and investigation.

As part of its proposal, and if the anticipated position sensitivity levels are specified in paragraph (c) above, the Offeror shall notify the Contracting Officer of (1) its proposed personnel who will be subject to a background check/investigation and (2) whether any of its proposed personnel who will work under the contract have previously been the subject of national agency checks or background investigations.

e. Investigations are expensive and may delay performance, regardless of the outcome of the investigation. Delays associated with rejections and consequent re-investigations may not be excusable in accordance with the FAR clause, Excusable Delays – see a.

Accordingly, if position sensitivity levels are specified in paragraph (c), the Offeror shall ensure that the employees it proposes for work under this contract have a reasonable chance for approval.

f. Typically, the Government investigates personnel at no cost to the Contractor. However, multiple investigations for the same position may, at the Contracting Officer’s discretion, justify reduction(s) in the contract price of no more than the cost of the additional investigation(s).

g. The Contractor shall include language similar to this “HHS-Controlled Facilities and Information Systems Security” language in all subcontracts that require subcontractor personnel to have the same frequency and duration of (1) physical access to an HHS- controlled facility; (2) logical access to an HHS-controlled information system; (3) access to sensitive HHS data/information, whether in an HHS-controlled information system or in hard copy; or (4) any combination of circumstances (1) through (3).

h. The Contractor shall direct inquiries, including requests for forms and assistance, to the Contracting Officer or designee.

i. Within 7 calendar days after the Government’s final acceptance of the work under this contract, or upon termination of the contract, the Contractor shall return all identification badges to the Contracting Officer or designee.

C.5.5 Other Administrative Vendors operating in the state of New Mexico are subject to payment of the New Mexico Gross Receipts Tax (NM GRT).

The Contractor shall have a complete understanding of the IHS security policy and procedures and comply with such security requirements, including user access and verification requirements such as levels of access, password protection and firewalls. The Contractor shall maintain physical security at all facilities housing the activities under this contract.

The Contractor agrees to comply with the applicable security requirements. The Contractor agrees to establish and follow security precautions considered by IHS to be necessary (which are subject to change during the contract) to ensure proper and confidential handling of data and information. This information is more specifically addressed in the IHS Information Security Program Policy. Current policy also requires all contractor staff performing work on IHS projects and/or connecting to IHS systems to have a Background Investigation (including fingerprints and credit release). The investigation process is initiated during hiring and a pre-clearance is required prior to commencement of duties. The Contractor shall ensure that no prospective hires appear on the Office of Inspector General (OIG) exclusion list of convicted felons (http://exclusions.oig.hhs.gov/). All costs associated with Background Investigation are to be borne by the Contractor; the Government will conduct the BI and will advise the Contractor of the costs.

Some information included in this task may be protected by the provisions of the Privacy Act of 1974 and/or the HIPAA Privacy Rule. All personnel assigned to this task will take the proper precautions to protect such information from disclosure.

The Government will retain rights to any intellectual property produced in the course of this task. The Contractor shall not divulge or disclose information received and discussed regarding data considered proprietary to other Contractors collaborating on or with this project.

Appendix A - Business Associate Agreement (BAA) Pursuant to the Health Insurance Portability and Accountability Act (HIPAA) of 1996; its implementing regulations, the Standards of Privacy of Individual Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E (“Privacy Rule”), and 45 C.F.R. Parts 160 and 164, Subparts A and C (“Security Rule”); and the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”), Title XIII, Subtitle D of the American Reinvestment and Recovery Act of 2009, Pub. L. No. 111-5, 123 Stat. 115 (2009) (“ARRA”), the Indian Health Service is required to enter into an agreement with the Business Associate, pursuant to which the Business Associate shall comply with and appropriately safeguard Protected Health Information ("PHI”) that it will use and disclose when performing functions, activities or services ("Services") for the Indian Health Service pursuant to this Contract. The Business Associate by signing the Contract shall comply with the following terms in addition to other applicable Contract terms and conditions relating to the safekeeping, use and disclosure of PHI.

Section 1 - Definitions Terms used in this Agreement, if not otherwise defined, shall have the same meaning as those terms contained within the Privacy Rule and the Health Information Technology for Economic and Clinical Health (HITECH) Act.

a. Breach: “Breach” shall mean the unauthorized acquisition, access, use, or disclosure of Protected Health Information (defined hereinafter) which compromises the security or privacy of such information, except where an unauthorized person to whom such information is disclosed would not reasonably have been able to retain such information;

b. Covered Entity: "Covered Entity" shall mean the Indian Health Service (IHS);

c. De-identified protected health information: “De-identified protected health information” shall have the same meaning as the term “de-identified protected health information” in 45 C.F.R. § 164. 514;

d. Designated Record Set: "Designated Record Set" shall mean (1) a group of records maintained by or for a covered entity that is: (i) The medical records and billing records about individuals maintained by or for a covered health care provider, (ii) The enrollment, payment, claims adjudication, and case or medical management record systems maintained by or for a health plan, or (iii) Used, in whole or in part, by or for the covered entity to make decisions about individuals. (2) For purposes of this paragraph, the term record means any item, collection, or grouping of information that includes protected health information and is maintained, collected, used, or disseminated by or for a covered entity; (45 C.F.R. § 164.501)

e. Electronic Health Record: “Electronic Health Record” shall mean an electronic record of health- related information on an individual that is created, gathered, managed, and consulted by authorized health care clinicians and staff;

f. Individual: "Individual" shall have the same meaning as the term "individual" in 45 C.F.R. § 164.501 and shall include a person who qualifies as a personal representative in accordance with 45 C.F.R. § 164.502(g);

g. Limited Data Set: “Limited Data Set” shall have the same meaning as the term “limited data set” in 45 C.F.R. § 164. 514(e)(2);

h. Privacy Rule: "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E;

i. Protected Health Information: "Protected Health Information" or “PHI” shall have the same meaning as the term "protected health information" in 45 C.F.R. § 160.103;

j. Required By Law: "Required By Law" shall have the same meaning as the term "required by law" in 45 C.F.R. § 164.501;

k. Secretary: "Secretary" shall mean the Secretary of the United States Department of Health and Human Services or her designee;

l. Unsecured Protected Health Information: “Unsecured Protected Health Information” or “Unsecured PHI” shall mean protected health information that is not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of a technology or methodology specified by the Secretary in guidance on the HHS website issued under section 13402(h)(2) of the HITECH Act.

Section 2 - Compliance The Business Associate agrees to comply with the business associate contract requirements under the Privacy Rule, the HITECH Act and the provisions of this Agreement throughout the term of this Agreement. The Business Associate agrees that it will require all of its agents, employees, subsidiaries, affiliates and subcontractors, to whom the Business Associate provides Personal Health Information (PHI), or who create or receive PHI on behalf of the Business Associate for the IHS, to comply with the Privacy Rule and the HITECH Act, and to enter into written agreements with the Business Associate that provide the same restrictions, terms and conditions as set forth in this Agreement.

In the event the Business Associate awards a subcontract under the Contract pursuant to which the Business Associate will disclose PHI to the subcontractor, notwithstanding any clause to the contrary contained in the Contract, the Business Associate agrees to obtain the IHS Contracting Officer’s written consent prior to awarding such subcontract.

Section 3 - Permitted Uses and Disclosures The Business Associate shall not use or disclose PHI except to perform functions, activities or services for or on behalf of the IHS as provided for in this Agreement, the Privacy Rule, the HITECH Act or other applicable law. The Business Associate agrees that it may use or disclose PHI on behalf of the IHS only (1) upon obtaining the authorization of the patient to whom the PHI pertains (45 C.F.R. §§ 164.502(a) (1) (iv) and 164.508(b)); (2) for the purpose of treatment, payment or health care operations (45 C.F.R. §§ 164.502(a)(1)(ii), and 164.506)), unless disclosure has been restricted pursuant to the HITECH Act at § 13405(a), or (3) without an authorization or consent, if in accordance with 45 C.F.R. §§ 164.506, 164.5 10, 164.512, 164.514(e), 164.514(f) or 164.514(g). The Business Associate shall use and disclose PHI in compliance with each applicable requirement of 45 C.F.R. § 164.504(e), which section is fully incorporated herein. Except as otherwise limited in this Agreement, the Business Associate may use PHI for the management and administration of the Business Associate or to carry out responsibilities that are required of it by law (45 C.F.R. § 164.502(e)(4)(i)).

Section 4 - Safeguards The Business Associate shall develop and use appropriate procedural, physical and electronic safeguards to protect against the use or disclosure of PHI in a manner not permitted by the Privacy Rule or this Agreement. The Business Associate will limit any use, disclosure or request for use or disclosure of PHI to the minimum amount necessary to accomplish the intended purpose of the use, disclosure or request in accordance with the applicable requirements of the Privacy Rule. As mandated by the HITECH Act, Privacy Rule sections 164.308 (administrative safeguards requirements), 164.310 (physical safeguards requirements), 164.312 (technical safeguards requirements) and 164.316 (policies and procedures and documentation requirements) shall apply to the Business Associate in the same manner that such sections apply to covered entities under the Privacy Rule.

Section 5 – Minimum Necessary Prior to the Secretary issuing guidance on what constitutes “minimum necessary” for purposes of the Privacy Rule, the Business Associate will limit, to the extent practicable, any use, disclosure or request for use or disclosure of PHI (other than those uses, disclosures or requests for use or disclosure of PHI set forth at 45 CFR section 164.502(b)(2)) , to the Limited Data Set, or, if needed, to the minimum amount necessary to accomplish the intended purpose of such use, disclosure or request, respectively. Upon the effective date of the Secretary’s ”minimum necessary” guidance, the Business Associate will limit any use, disclosure or request for use or disclosure of PHI, to the minimum amount necessary as set forth in such guidance.

Section 6 - Safeguards for Electronic PHI The Business Associate shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of any electronic PHI that it creates, receives, maintains, or transmits on behalf of the IHS as required by 45 C.F.R. Part 164, subpart C, Security Standards for the Protection of Electronic Health Information. Section 4 above shall apply in full to this Section 6.

Section 7 - Reporting of Unauthorized Uses or Disclosures The Business Associate shall promptly report to the IHS any knowledge of uses or disclosures of PHI that are not in accordance with this Agreement or applicable law. In addition, the Business Associate shall mitigate, to the extent practicable, any harmful effect that is known to the Business Associate of a use or disclosure of PHI by the Business Associate in violation of the requirements of the Privacy Rule or the HITECH Act. For those uses or disclosures that involve a breach of the security of any unsecured PHI received from, or created or received on behalf of, the IHS, the Business Associate shall comply with the requirements set forth in Section 8 below.

Section 8 - Reporting of Breach of Unsecured PHI The Business Associate shall notify the IHS of a breach of the security of any unsecured PHI that the Business Associate received from, or created or received on behalf of, the IHS within thirty (30) calendar days after the discovery of the breach by the Business Associate, its employees, officers and/or other agents unless a law enforcement official has determined that such notification would impede a criminal investigation or cause damage to national security, in which case the notification shall be delayed in accordance with the requirements of 45 C.F.R. § 164.412.. Such notice shall include, to the extent possible, the identification of each individual whose unsecured PHI has been, or is reasonably believed by the Business Associate to have been, accessed, acquired, or disclosed during such breach; a brief description of the circumstances of the breach of security, including the date of the breach and the date of the Business Associate’s discovery of the breach; and the type of unsecured PHI involved in the breach. In the event notification is delayed, evidence demonstrating the necessity of the delay shall accompany the notification. A breach shall be treated as discovered as of the first day on which such breach is known to Business Associate (including any person, other than the individual committing the breach that is an employee, officer or other agent of Business Associate) or should have reasonably been known to Business Associate (or person) to have occurred.

Section 9 – Maintenance of Records and Accounting of Disclosures The Business Associate shall maintain records of PHI received from or created or received on behalf of the IHS and shall document subsequent uses and disclosures of such information by the Business Associate. The Business Associate shall, within 5 calendar days after receiving a request from the IHS, provide to the IHS such information as the IHS may require to fulfill its obligations to provide access to, provide a copy of, and account for disclosures with respect to PHI pursuant to the Privacy Rule (e.g., 45 C.F.R. § 164.528) (individual request for an accounting of PHI disclosures), the HITECH Act and other applicable law. In accordance with the requirements of HITECH Act section 13405(c), beginning on [need to determine if BA already has EHR system and then put in applicable date based on requirement of HITECH section 13405(c)(4)], the Business Associate shall account for all disclosures of PHI for treatment, payment and health care operational purposes.

Section 10 - Maintenance of Records and Accounting: Individual Access The Business Associate shall maintain a Designated Record Set for each patient for which it has PHI. In accordance with a patient's right to access his/her PHI under the Privacy Rule, the Business Associate shall make available all PHI in the patient's Designated Record Set to the patient to whom that information pertains, or, upon the request of the patient, to that patient's authorized representative, in compliance with 45 C.F.R. § 164.524. Availability shall be made within 5 calendar days of receipt of a request.

Section 11 – Disclosure for Purposes of Verifying Compliance Upon request, the Business Associate shall make available to the IHS or to the Secretary, PHI and the Business Associate's internal practices, books and records, including its policies and procedures and any agreements required by Section 2 herein that it has with subcontractors, vendors and other agents relating to the use and disclosure of PHI received from the IHS, or created or received by the Business Associate on behalf of the IHS, for purposes of determining both the Business Associate’s and the IHS’s compliance with the Privacy Rule and the HITECH Act and its implementing regulations. The Business Associate shall not disclose PHI to any requesting party other than as provided for in this Section and Sections 3 and 10 above. The Business Associate shall forward all other disclosure requests to the IHS for processing, except those it receives directly from individuals in accordance with Section 10 above.

Section 12 - Amendments of Information The Business Associate shall, within 5 calendar days of a request by the IHS, make PHI available to the IHS for the IHS to fulfill its obligations pursuant to the Privacy Rule to amend PHI and shall, as directed by the IHS, within 5 calendar days of receipt of such direction, incorporate any amendments into PHI held by the Business Associate.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .