View the file

Other files for this federal contract opportunity

Other files attached to International Technical, Operational, and Professional Support Services (ITOPS 4. 0), newest first.
File Type Posted
Real RFTOP South Africa 042923.pdf PDF
RFP 75D30123R63271 042223.pdf PDF
RFTOP Sample BRAZIL QA 042923.pdf PDF
Admendment 0001 050423.pdf PDF
RFTOP GHANA QA_042923.pdf PDF
Sample RFTOP Brazil 042923.pdf PDF
Real RFTOP Ghana 042923.pdf PDF
Real RFTOP Rwanda 042923.pdf PDF
RFTOP South Africa 042923.pdf PDF
IDIQ QA 042223.pdf PDF
RFTOP RWANDA Q A_ 042923.pdf PDF
14 QASP IDIQ.doc DOC document
10 RFTOP RWANDA QA format.docx DOCX document
6 Past Performance Survey.doc DOC document
RFP 75D30123R63271 031516.pdf PDF
11 RFTOP GHANA QA format.docx DOCX document
4 Real RFTOP South Africa.pdf PDF
13 Sample Business Proposal Spreadsheet.xlsx XLSX spreadsheet
9 Sample RFTOP BRAZIL QA format.docx DOCX document
8 IDIQ QA format.docx DOCX document
7 Proposal Preparation Certification V 2 0.docx DOCX document
5 Sample Consent Letter.docx DOCX document
12 RFTOP SOUTH AFRICA QA format.docx DOCX document
3 Real RFTOP Ghana.pdf PDF
1 Sample RFTOP Brazil 2_1_2023.pdf PDF
Show all 25

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Request for Task Order Proposal (RFTOP)

Note: This task will be awarded.

RFTOP NUMBER OR NAME Rwanda

This RFTOP incorporates provisions and clauses documented therein in the Indefinite Delivery, Indefinite Quantity (IDIQ) RFP 75D30122R63271.

This RFTOP is a Cost-Reimbursement (Cost Plus Fixed Fee task) type.

ITOPSS 3.0 Request for Task Order Proposal (RFTOP)

1.Required Security Level Level 5 (Public Trust)

2.Type of Task Order Cost Plus Fixed Fee

3. Security Background

Requirements

Contractor is required to perform security/background checks prior to task order performance, based on the security level required.

4. PWS Reference C.3.2.3 Professional Support Services

5. Period of Performance 6/15/2023 to 06/14/2028

7.Number of Option Years, if applicable

Place of Performance Rwanda

8.Task Order Administration Not Applicable since this is a RFTOP

AUTHORITY TO OBLIGATE THE GOVERNMENT: The Task Order Contracting Officer is the only individual who may legally commit the U.S. Government to the expenditure of public funds. The Contractor may not incur costs chargeable to this task order before the receipt of either a task order signed by the Contracting

Officer or a specific written authorization from the Contracting Officer.

SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS

Base Year

CLIN SUPPLIES / SERVICES QTY /

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL

COST PLUS

FIXED FEE

0001 Provide ITOPSS support services per as outlined Section C of the task order.

Service Letter A - Senior Research &

Evaluation Specialist

Severable Services

Period of Performance: 6/15/2023 to

6/14/2028

1 Job $ $ $

TOTAL

Note: All labor and non-conference travel will be on the same CLIN.

Option Year 1

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

1001 Provide ITOPSS support services per as outlined in Section C of the task order.

Period of Performance: 6/15/2024 to

6/14/2025

1 Job

Option Year 2

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

2001 Provide ITOPSS support services per as

Period of Performance: 6/15/2025 to

6/14/2026

Option Year 3

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

3001 Provide ITOPSS support services per as outlined Section C of the task order.

Period of Performance: 6/15/2026 to

6/14/2027

Option Year 4

UNIT

ESTIMATED

COST

FIXED

FEE

TOTAL COST

PLUS FIXED

FEE

4001 Provide ITOPSS support services per as

Period of Performance: 6/15/2027 to

6/14/2028

Recapitulation:

CLIN ESTIMATED COST FIXED FEE TOTAL COST

PLUS FIXED FEE

Professional Support Services – Rwanda

C. PERFORMANCE-BASED WORK STATEMENT (PWS)

C.1 Background and Need:

The Centers for Disease Control and Prevention’s (CDC) mission is to promote the health and quality of life by preventing and controlling disease, injury, and disability. As part of this mission, CDC is tasked with implementing programs to ensure that people around the world will live safer, healthier lives through protecting Americans at home and abroad from health threats via international prevention, detection and response networks and promoting CDC and the United

States Government as trusted and effective resources for health development around the globe.

CDC addresses critical global public health challenges through working with a diverse set of partners to support the development and implementation of culturally-appropriate public health interventions. Through health promotion activities, both domestically and abroad, CDC contributes to reductions in global morbidity and mortality.

The mission of the Centers for Disease Control (CDC) is to promote the health and quality of life of people by preventing and controlling disease, injury, and disability. CDC through its newly created Center for Global Health (CGH) is in a position to bring its scientific expertise and credibility to the U.S. Global Health Initiative (GHI): “to protect the health of our people, while saving lives, reducing suffering, and supporting the health and dignity of people everywhere.” The key elements of CDC’s global health strategy are:

• Assist Ministries of Health to plan, effectively manage, and evaluate health programs;

• Achieve goals adopted by USG programs and international organizations to improve health, including disease eradication and elimination targets;

• Expand CDC’s global health programs that focus on the leading causes of mortality, morbidity and disability, especially chronic disease and injuries;

• Generate and apply new knowledge to achieve health goals; and

• Strengthen health systems and their impact.

As part of this mission, CDC is tasked with implementing programs in international settings, primarily in developing countries. To reach these goals HHS/CDC focuses on the following major program areas: HIV/AIDS, Malaria, Global Immunizations, Influenza, Global Disease Detection, Safe Water, Injury & Violence, Birth Defects & Developmental Disability, Field Epidemiology and

Laboratory Training, Sustainable Management Development, Reproductive Health, Workforce and

Career Development, and Global Preparedness & Program Coordination.

The first phase of the U.S. President’s Emergency Plan for AIDS Relief (PEPFAR I) was a 5-year, $15 billion multi-faceted approach to combating HIV/AIDS in more than 100 countries around the world. Since the United States Leadership Against HIV/AIDS, Tuberculosis, and Malaria Act of

2003 (Public Law 108-25) was signed by the President on May 27, 2003, the Office of the U.S.

Global AIDS Coordinator (OGAC) has coordinated the U.S. Government’s world-wide response to

HIV/AIDS. In full partnership with the U.S. Agency for International Development, the U.S.

Departments of Commerce, Defense, and Labor, and the Peace Corps, the U.S. Department of

Health and Human Services (including the Centers for Disease Control and Prevention [CDC], the

National Institutes of Health [NIH], and the Health Resources & Services Administration [HRSA]) provides essential technical assistance to implement PEPFAR.

On July 30, 2008, President George W. Bush signed into law the Tom Lantos and Henry J. Hyde

United States Global Leadership Against HIV/AIDS, Tuberculosis, and Malaria Reauthorization

Act (H.R. 5501) which reauthorizes PEPFAR to continue with a similar mandate for another five years at higher funding levels. The second phase of PEPFAR, or PEPFAR II, expanded HIV prevention, care, and treatment, building on the successes of PEFPAR I and advancing in several important new directions, including:

• Ensuring that programs are sustainable, country-owned and country-driven

• Transitioning from an emergency response to promotion of sustainable country programs

• Strengthen partner government capacity to lead the response to this epidemic and other health demands

• Expand prevention, care, and treatment in both concentrated and generalized epidemics.

• Integrating and coordinating HIV/AIDS programs with broader global health programs to maximize impact on health systems

• Investing in innovation and operations research to evaluate impact, improve service delivery and maximize outcomes

The PEPFAR program is now in phase 3 (2013-present) and is focused on transparency and accountability for impact, as well as accelerating core interventions for epidemic control. PEPFAR is investing resources strategically and geographically to reach populations at greatest risk with evidence-based programs. The report also provides insight into PEPFAR’s five Action Agendas— the foundation on which an AIDS-free generation will be achieved. The action agendas include:

Impact; Efficiency; Sustainability; Partnership; and Human Rights.

At CDC, the Center for Global Health Division of HIV/AIDS and Tuberculosis (DGHT) has been actively involved in PEPFAR since its beginning in 2003, with its highly-trained behavioral, health, and laboratory scientists, epidemiologists, medical officers, and public health advisors working at headquarters and in the field and regional offices to support national strategies for sustainable, integrated HIV/AIDS prevention, care, and treatment programs. DGHT Atlanta and field offices in over 50 countries provide expertise in the areas of HIV/AIDS prevention, care, and treatment, infrastructure development, laboratory capacity building, monitoring and evaluation, surveillance, and public health evaluation research.

CDC-Rwanda is using various cooperative agreements (CoAgs) with the following partners/grantees to achieve the goals listed above:

1) Ministry of Health (MOH) – CDC-RFA-GH – GH002202

2) Rwanda Biomedical Center – GH19-1927 – GH002203

3) Society for Family Health – GH19-1940 – GH002206

4) ICAP – GH21-2141 – GH002347

5) ICAP – GH19-1942 – GH002171

http://www.pepfar.gov/about/agendas/impact/index.htm http://www.pepfar.gov/about/agendas/efficiency/index.htm http://www.pepfar.gov/about/agendas/sustainability/index.htm http://www.pepfar.gov/about/agendas/partnership/index.htm http://www.pepfar.gov/about/agendas/humanrights/index.htm

C.2.A Overall Services and Service Information

Individual Service Tables follow and should correspond with Service Letters and Titles identified in the below table.

All services require full-time, 40-Hour work weeks unless noted otherwise.

Service

Ltr

Service Title Approx. # of

People to

Provide

Services

A Senior Research and Evaluation Specialist 1

Security Levels (to be identified in the Service Table for each Service)

Level 1 – NACI (Non-Sensitive) – Includes Name, Fingerprint Checks, and Written Inquiries

(Most candidates will fit into this category.

Level 5 – NACI (NACI + Credit Check) and possible MBI/LBI

Level 6 – Background Investigation - Auditing; Security; Access to data covered by the Privacy

Act; or Access to sensitive, proprietary, or financial information, including access through, and/or control over, automated information systems.

C.2.B Future Services

• Additional services, applicable to this task order, may be required in the future. Additional services within 30% of those originally competed will not be re-competed for the duration of this task order. Services that go beyond the 30% limit will be competed under a new

Request for Task Order Proposal (RFTOP).

Example: 10 labor sources (service letters) are initially competed and awarded o Task Order would allow for No More Than (3) additional labor sources on this task order.

C.2.C Service Table A:

Service Title: Senior Research & Evaluation Specialist

Estimated Period of Performance: 6/15/2023 to 6/14/2028

# of Options, if applicable: 4

Place of Performance: Rwanda

Embassy Access and Security Level: Level 5

Service Objectives: Provide a broad range of surveillance, epidemiologic studies, and evaluation support to CDC

Rwanda to ensure surveillance and epidemiologic studies conducted are done in compliance with good clinical practices, including but not limited to regulatory oversight and data quality.

A.1 Task Requirements:

A.1.1 Support CDC Rwanda in all surveillance, epidemiologic studies, and evaluation endeavors, through hands on support, consultancies, and scheduled meetings.

A.1.2 Provide technical and expertise advice on surveillance, epidemiologic studies, and evaluation matters to CDC

Rwanda staff.

A.1.3 Provide technical assistance and training on surveillance, research and evaluation methodology and program evaluation.

A.1.4 Develop protocols for program evaluations, operations research, surveys and surveillance.

A.1.5 Adapt and present approved CDC curriculum on protocol development, research methods, including data collection, data management and analysis, data interpretations, and manuscript writing for CDC Rwanda.

A.1.6 Develop protocols and data collection tools and provide guidance on data collection, implementation and data analysis and write-up.

A.1.7 Support a collaborative approach in program design, implementation, monitoring, and evaluation of program activities.

A.1.8 Build capacity within the CDC Rwanda’s programs teams and implementing partners to improve submitted surveillance and scientific products for clearance, including protocols, abstracts, manuscripts.

A.1.9 Review scientific evidence pertaining to disease prevention, and care and treatment support programs at

CDC.

A.1.10 Disseminates results from CDC-funded surveillance, epidemiologic studies and program evaluations conducted by implementing partners.

A.1.11 Monitor on-going studies to ensure quality, valid and reliable data.

A.1.12 Monitor data, records, and processes for ethical assurance.

A.1.13 Travel to and present on behalf of CDC Rwanda at CDC-approved national conferences, meetings and workshops as requested. These conferences may include INTEREST, APHA, IAS, etc. Note- Travel for conferences are not allowed without a formal bilateral modification by the Contract Officer.

A.1.14 Participate in SIMS visits, data quality assessments, when requested by CDC Rwanda senior management.

A.1.15 Disseminate program and study results in collaboration with CDC Rwanda staff and implementing partners through scientific journals, periodic reports, and public presentations.

A.1.16 Support CDC-Rwanda’s key partners (Ministry of Health and RBC) in conducting surveillance and epidemiologic studies on emerging public health threats and infectious diseases.

A.1.17 Support analysis and interpretation of CDC Rwanda program data through triangulation of surveys, surveillance, and program data.

A.1.18 Complete special projects as instructed.

Task Deliverables:

Deliverables/Reports Task Requirement Recipient Due Date

Training manuals on study design and data analysis

A.1.5 COR and DDSR Three months after task order is awarded.

Report on the review and documentation of statistical sections of all protocols developed by

Rwanda Biomedical

Center, Institute of

HIV/AIDS Disease

A.1.4 COR and DDSR Monthly

Prevention and Control and Rwanda MOH.

Report on training and of results of monthly and quarterly data analysis on collected CDC Rwanda and PEPFAR supported program data.

A.1.3; A.1.5; A.1.11 COR and DDSR Once every month and quarter on date requested by COR

Progress Report A.1.1 – A.1.18 COR and DDSR 5th workday of every month

Activity Report A.1.8 COR and DDSR 10 days after the end of every quarter

Project Report A.1.18 COR and DDSR 10 days after completion of projects

Trip Report A.1.14 – A.1.15 COR and DDSR 5 days following completion of travel

Minimum Qualifications and/or Certifications:

• Expert knowledge of statistic, and epidemiology, to design, conduct, and analyze studies to develop and evaluate protocols pertaining to HIV/AIDS, TB, malaria, and other infectious diseases.

• Minimum of five years’ experience in advanced analysis using SPSS, SAS, STATA and data management.

• Experience working with the federal cooperative agreement recipients and budget processes and cycles

• Ph.D. in Statistics with a Masters in Science.

• Experience working in an international setting for at least five years

• Required language skills English (Level IV: Fluency in speaking, reading, writing and understanding of

English )

• Knowledge of French Language.

Only U.S. citizens or non-U.S. citizens who have lived in the U.S. at least three of the last five years are eligible to provide services under this task order.

The exception to this is an incumbent non-U.S. citizen contractor employee with current, valid security clearance for physical and logical access to CDC and embassy facilities and network. If the exception stated above is used, do not include any contractor employee who is considered an ordinarily resident in your proposal. The definition of an ordinarily resident is listed below.

Ordinarily resident: A U.S. citizen or Third Country National who: (1) is a local resident;(2) has legal, permanent resident status within the host country; and (3) is subject to host country employment and tax laws. This also includes host country citizens.

Travel Amount (Only applies to performance of Task Order):

1 trip to USA for an estimated 5 days.

5 trips in country for an estimated 2 days each.

2 trips to African countries for an estimated 5 days each

Travel needs during option periods will be evaluated at the time of task order renewal.

Note- Travel for conferences are not allowed without a formal bilateral modification by the Contract

Officer.

Not-To-Exceed (NTE) $_15,000_USD/Per Option Period

(Includes Transportation, Lodging/M&IE, etc.) ***Personal Development is not Allowable***

Government-Furnished Property (to include but not limited to laptop, blackberry, access to printers and office supplies, etc.):

Laptop

Blackberry or Samsung or Iphone

Software required by CDC-Rwanda

Office supplies

Training and presentation supplies

Contractor Furnished Property, if applicable:

N/A

C.3 Place of Performance

Rwanda

C.4 Performance-Based Matrix

C.5 Authority to Obligate Government

The Task Order Contracting Officer is the only individual who may legally commit the U.S.

Government to the expenditure of public funds. The Contractor may not incur costs chargeable to this task order before the receipt of either a task order signed by the Contracting Officer or a specific written authorization from the Contracting Officer.

Service

Required

Measures of

Success Indicators

Standards -

Criteria for

Acceptance

Method of

Surveillance

"Incentives"

Positive or

Negative

All Tasks and

Deliverables from C.

Service Table

A

Contractor shall perform all tasks/services in accordance with

(IAW) applicable regulatory standards, task order requirements, and procedural guidelines as stated in this task order.

100% of

Services/tasks adhere to applicable regulatory standards, task order requirements, and procedural guidelines as stated in this task order.

In addition, reference the attached Quality

Assurance

Surveillance Plan.

COR

approval and observation.

Positive: Past

Performance and

Evaluation will be used in determining awards for future task orders for similar services;

Negative:

Performance evaluations will include any services that failed to meet acceptable standards and will be used in determining awards for future task orders for similar services

Timeliness –

(1)All tasks, reports, and deliverables completed within due date specified in Section C.2

100% of time –All tasks, reports, and deliverables shall be performed by due date specified in Section C.2 unless delay is approved in advanced by COR.

In addition, reference the attached Quality

Assurance

Surveillance Plan.

COR

approval and observation.

Positive: Past

Performance and

Evaluation will be used in determining awards for future task orders for similar services;

Negative:

Performance evaluations will include any services that failed to meet acceptable standards and will be used in determining awards for future task orders for similar services.

C.6 Security Background Requirements

Contractor employees are required to receive Level 5/NACI security/background checks prior to task order performance. The security process is initiated when contracting organization provides contractor employee’s NACI results to the Office of Safety, Security and Asset Management personnel and personal identifying information to the Headquarters Contracting Officer

Representative.

D. Not Used

E. Refer to Base Contract Section E

F. Refer to Base Contract Section F

F.1 See CLINS for Period of performance.

G. CONTRACT/TASK ORDER ADMINISTRATION DATA

The Clauses found in the IDIQ base shall contract remain in full force and effect for this Task Order.

G.1 See Cover for Contact Information

G.2 CDCA_G01101 Contractor Billing Instructions for Cost-Type Contracts (Mar 2022)

The Contractor shall submit a detailed breakout of costs and supporting backup information and shall place the following signed Contractor Certification on each invoice/voucher submitted under this contract:

I certify that this voucher reflects (fill in Contractor’s name) request for reimbursement of allowable and allocable costs incurred in specific performance of work authorized under Contract

(fill in contract number)/Task (fill-in task order number, if applicable), and that these costs are true and accurate to the best of my knowledge and belief.

(Original Signature of Authorized Official)

Typed Name and Title of Signatory

Introduction

Reimbursement procedures related to negotiated cost-type contracts require that Contractors submit to the Government adequately prepared claims. The instructions that follow are provided for

Contractors’ use in the preparation and submission of invoices or vouchers requesting reimbursement for work performed. The preparation of invoices or vouchers as outlined below will aid in the review and approval of claims and enable prompt payment to the Contractor.

1. Forms to Be Used

In requesting reimbursement, Contractors may use the regular Government voucher form, Standard

Form 1034, “Public Voucher for Purchases and Services Other Than Personal,” and Standard Form

1035, “Continuation Sheet,” or the Contractor’s own invoice form. If the Contractor desires to use the Government’s standard forms, a request for the forms should be submitted to the Contracting

Officer. If the Contractor uses his own invoice, the billing must conform to the instructions set forth herein.

2. Submission of Invoices or Vouchers

Will be conducted in accordance with HHSAR 352.232-71 Electronic Submission of Payment

Requests

3. Preparation of Invoices or Vouchers- All invoices or vouchers must include the following information:

a. Summary of All Costs – typically inserted on the Standard Form 1034

A summary of all current costs must be shown. This summary consists of a list identifying the general categories and the amounts incurred during the period covered by the billing, together with the portion of fixed fee (if any) payable for that period. The reimbursable costs incurred and the dates of the period for which the charges are claimed must fall within the period specified in the contract.

b. Details of Costs Claimed – typically inserted on the Standard Form 1035 (continuation sheet)

A detailed breakdown must be provided to substantiate the categories shown on the summary of costs. The following describes some of the categories that might appear on your billings:

(1) Direct Labor

Direct Labor costs consist of salaries and wages paid for scientific, technical, and other work performed directly for the contract and pursuant to the contract terms. Labor costs, excluding fringe benefits and overtime premium pay, will be billed as follows:

List the titles and amounts for employees whose salaries or wages, or portions thereof, were charged to the contract; show the rate (or hours) worked, and amount for each individual. The cost of direct labor, which is charged directly to the contract, must be supported by time records maintained in the contractor’s office.

(2) Fringe Benefits

If it is the Contractor’s established practice to treat fringe benefits as a direct cost, such costs should be billed separately as a single item.

NOTE: Fringe benefits, bonuses, etc., are usually treated as indirect costs for inclusion in the overhead pool; however, they may be treated as direct labor costs or as an “Other Direct Charge” if such treatment is in accordance with the Contractor’s established accounting procedures.

(3) Premium Pay

Premium pay is the difference between the rates and amounts paid for overtime or shift work and amount normally paid on a straight time basis. Generally such pay is not included in the direct labor base and should not be included in the billing for “direct labor” unless the Contractor has consistently followed this practice in the past as a matter of policy. Premium pay of any kind unless provided for in the contract must be authorized by the Contracting Officer in advance. Billings for unauthorized premium pays have caused frequent delays in payment due to suspensions and exchange of correspondence. Citations of authorization for premium pay will avoid delays in payment. Authorized premium pay may be shown as a single item on the summary of costs.

However, it must be separately itemized for each position, or job category, showing the amount, and a citation of the Contracting Officer’s letter of authorization on the continuation sheet of the invoice or voucher.

(4) Materials and Supplies

Only those items, which the Contractor normally treats as “direct costs”, should be claimed under this heading. Major classifications of material only should be billed separately under appropriate classification. Items costing less than $25.00 may be listed by category of materials or supplies.

Show the description and dollar amount of individual classifications. All such charges must be supported by the Contractor’s office records.

(5) Travel

When authorized in the contract as a direct cost, travel costs that are directly related to specific contract performance may be billed as a direct cost. Travel cost detail should show:

(a) Name of traveler and official title,

(b) Purpose of trip,

(c) Dates of departure and return to starting point (station or airport),

(d) Transportation costs, identified as to rail, air, private automobile (including mileage and rate) and taxi.

(e) If claim for subsistence is on per diem basis, show number of days, rate and amount, as authorized in contract.1 If claim is based on actual cost of subsistence, show, on a daily basis, the amounts claimed for lodging and meals separately.

(f) Reference to Contracting Officer’s letter of authorization if required by contract.

1For purposes of computing per diem charges in lieu of actual subsistence charges, unless otherwise provided in the contract, a day is divided into four quarters that begin at 12 midnight, 6:00 AM, 12 noon, and 6:00 PM. For example, at an authorized per diem rate of $35.00 per day, a traveler who departed at 9:15 AM on July 15 and returned at 6:45 PM on July 18 would be entitled to $131.25.

(6) Consultant Fees

Identify the consultant by name, number of days utilized, and amount of fee.

(7) Equipment

Nonexpendable personal property must be specifically approved in writing by the Contracting

Officer or authorized by the terms of the contract. Billing data should include a description of item, make model, quantity, unit cost, total cost, and date approved by the Contracting Officer, if applicable. A copy of the vendor’s bill may be submitted in lieu of the identifying information.

(8) Burden

Pending establishment of final contract indirect cost rates for each of the Contractor’s fiscal years, the Contractor will be reimbursed based on his submittal of provisional rates as set forth in the contract. The contract may provide for more than one type of indirect cost rate, such as overhead rate, and general and administrative expense rate, in which case the direct cost bases (e.g., direct labor, total direct cost, etc.)

(9) Fixed Fee

Ordinarily the fixed fee is stated in the contract as a lump sum and may be billed in the ratio of incurred costs to total estimated cost as set forth in the contract, with the final 15 percent to be billed on the final invoice or voucher. Contract terms govern the method of payments.

c. Cumulative Amount Claimed – typically inserted on Standard Form 1035 (continuation sheet) separate section/page

The Contractor must show the cumulative amounts claimed by categories from the contract award date through the date of the current invoice or voucher, as well as the estimated cost to complete per category.

QUICK CHECKLIST FOR INVOICE SUBMISSION:

• Standard Forms 1034 and 1035 recommended. If submitting own forms, statement must conform to billing instructions

• Quarterly billing as a minimum

• Vouchers must be collated

• Detail of Cost Claimed

G.3 CDCP_G010 Contract Communications/Correspondence

(Jul 1999)

The Contractor shall identify all correspondence, reports, and other data pertinent to this contract by imprinting thereon the contract number from Page 1 of the contract.

G.4 352.232-71 Electronic Submission of Payment Request

(a) Definitions. As used in this clause—

(1) “ Payment request” means a bill, voucher, invoice, or request for contract financing payment with associated supporting documentation. The payment request must comply with the requirements identified in FAR 32.905(b), “Content of Invoices” and the applicable Payment clause included in this contract.

(b) Except as provided in paragraph (c) of this clause, the Contractor shall submit payment requests electronically using the Department of Treasury Invoice Processing Platform (IPP) or successor system. Information regarding IPP, including IPP Customer Support contact information, is available at www.ipp.gov or any successor site.

(c) The Contractor may submit payment requests using other than IPP only when the Contracting

Officer authorizes alternate procedures in writing in accordance with HHS procedures.

(d) If alternate payment procedures are authorized, the Contractor shall include a copy of the

Contracting Officer's written authorization with each payment request.

(End of Clause)

H. Special Provisions

The Clauses found in the IDIQ base shall contract remain in full force and effect for this Task

Order.

Note : The non personal service clause is in Section H of the base contract.

H.1. Ability to Legally Provide Services Overseas

a. The Prime Contractor is responsible for acquiring all legally appropriate work permits and visas, without CDC assistance, to ensure that services are performed in accordance with host country requirements.

b. In the event that the Prime Contractor is unable to acquire all legally appropriate work permits and visas, after reasonable time has been allowed for host country appeals (if necessary), CDC may terminate the task order.

b.1. “Reasonable Time” is relative based upon each country’s circumstances. CDC has not set a timeline for making this decision, but will communicate directly with the Prime Contractor and COR throughout the process of acquiring all legally appropriate work permits and visas.

H.2. Information Security and/or Physical Access Security

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order

(hereafter “contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) employee will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal

Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology”

(IT), the term as used in this section includes computers, ancillary equipment

(including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal

Information Processing Standards Publication (FIPS) 199, Standards for Security

Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor on behalf of HHS regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the HHS Information

Security Program security requirements, outlined in the HHS Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing fisma@hhs.gov.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

3) Information Security Categorization. In accordance with FIPS 199 and National

Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II:

Appendices to Guide for Mapping Types of Information and Information Systems to

Security Categories, Appendix C, and based on information provided by the ISSO, CISO, or other security representative, the risk level for each Security Objective and the Overall

Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [X] Low [] Moderate [ ] High

Integrity: [] Low [X] Moderate [ ] High

Availability: [X] Low [] Moderate [ ] High

Overall Risk Level: [] Low [X] Moderate [ ] High

Based on information provided by the ISSO, Privacy Office, system/data owner, or other security or privacy representative, it has been determined that this solicitation/contract involves:

[] No PII [X] Yes PII

4) Personally Identifiable Information (PII). Per the Office of Management and Budget

(OMB) Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: social security number, date and place of birth, mother‘s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ ] Low [] Moderate [ ] High

5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at

32 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa) As implemented the term

“handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg.

63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for

Federal Information Systems and Organizations applicable baseline if handled by a

Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to HHS control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data shall be accomplished in accordance with NIST SP

800-88, Guidelines for Media Sanitization.

6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

7) Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by HHS or collected by the contractor on behalf of

HHS shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the

Contractor. Each Contractor employee or any of its subcontractors to whom any HHS records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and [CDC] policies. Unauthorized disclosure of information will be subject to the HHS/[CDC] sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

8) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol

Version 6 (IPv6).

9) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP

Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

10) Contract Documentation. The Contractor shall use provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

Document Deliverable

Title/Description

Due Date

Roster Roster By effective date of this contract

Contractor Employee

Non-Disclosure

Agreement (NDA)

Contractor Employee

Non-Disclosure

Agreement (NDA)

Prior to performing any work on behalf of

HHS

Privacy Threshold

Analysis (PTA)/

Privacy Impact

Assessment (PIA)

Assist in the completion of a PTA/PIA form

In conjunction with contract award

Training Records Copy of training records for all mandatory training

In conjunction with contract award and annually thereafter or upon request

Rules of Behavior Signed ROB for all employees

Initiation of contract and at least annually thereafter

Incident Response Incident Report (as incidents or breaches occur)

As soon as possible and without reasonable delay and no later than 1 hour of discovery

Incident Response Incident and Breach

Response Plan

Upon request from government

Personnel Security

Responsibilities

List of Personnel with defined roles and responsibilities

Prior to performing any work on behalf of

HHS

Personnel Security

Responsibilities

Off-boarding documentation, equipment and badge when leaving contract

Prior to performing any work on behalf of

HHS

11)

Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and

Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS

140-2 validated encryption solution.

c. Secure all devices (i.e.: desktops, laptops, mobile devices, etc.) that store and process government information and ensure devices meet HHS and CDC-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use have been validated under the

Cryptographic Module Validation Program to confirm compliance with FIPS 140-2.

The Contractor shall provide a written copy of the validation documentation to the

COR.

e. Use the Key Management system on the HHS personal identification verification

(PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.

Encryption keys shall be provided to CDC Office of Chief Information Security

Officer (OCISO).

12) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the CDC non-disclosure agreement, as applicable. A copy of each signed and witnessed NDA shall be submitted to the Contracting Officer (CO) and/or CO

Representative (COR) prior to performing any work under this acquisition.

Background

Investigation

Onboarding documentation when beginning contract

Prior to performing any work on behalf of

HHS

Certification of

Sanitization of

Government and

Government Activity-

Related Files, Information, and

Devices

Form or deliverables required by CDC

At contract expiration

Contract Initiation and

Expiration

If the procurement involves a system or cloud service, additional documentation will be required, such as

Disposition/Decommissi on Plan

At contract expiration

13) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The

Contractor shall assist the CDC Senior Official for Privacy (SOP) or designee with conducting a PTA for the information system and/or information handled under this contract in accordance with HHS policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002.

a. The Contractor shall assist the CDC SOP or designee in reviewing the PIA at least every three years throughout the system development lifecycle

(SDLC)/information lifecycle, or when determined by the CDC SOP that a review is required based on a major change to the system (e.g., new uses of information collected, changes to the way information is shared or disclosed and for what purpose, or when new types of PII are collected that could introduce new or increased privacy risks), whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable

HHS/CDC Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract.

Thereafter, the employees shall complete CDC Security Awareness Training (SAT), Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training (RBT) within 60 days of assuming their new responsibilities. Thereafter, they shall complete RBT at least annually in accordance with HHS policy and the HHS Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Memorandum.

All HHS employees and contractors with SSR who have not completed the required training within the mandated timeframes shall have their user accounts disabled until they have met their RBT requirement.

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior before accessing Department data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual CDC

Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines above.

D. Incident Response

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies. The HHS Policy for IT

Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by Federal Information Security

Modernization Act (FISMA) as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

OMB Memorandum M-17-12, “Preparing for and Responding to a Breach of Personally

Identifiable Information” (03 January 2017) states:

Definition of an Incident:

An occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.

Definition of a Breach:

The loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose.

It further adds:

A breach is not limited to an occurrence where a person other than an authorized user potentially accesses PII by means of a network intrusion, a targeted attack that exploits website vulnerabilities, or an attack executed through an email message or attachment. A breach may also include the loss or theft of physical documents that include PII and portable electronic storage media that store PII, the inadvertent disclosure of PII on a public website, or an oral disclosure of PII to a person who is not authorized to receive that information. It may also include an authorized user accessing PII for an other than authorized purpose.

The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII”.

Contracts with entities that collect, maintain, use, or operate Federal information or information systems on behalf of CDC shall include the following requirements:

1) The contractor shall cooperate with and exchange information with CDC officials, as deemed necessary by the CDC Breach Response Team, to report and manage a suspected or confirmed breach.

2) All contractors and subcontractors shall properly encrypt PII in accordance with

OMB Circular A-130 and other applicable policies, including CDC-specific policies, and comply with HHS-specific policies for protecting PII. To this end, all contractors and subcontractors shall protect all sensitive information, including any

PII created, stored, or transmitted in the performance of this contract so as to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

3) All contractors and subcontractors shall participate in regular training on how to identify and report a breach.

4) All contractors and subcontractors shall report a suspected or confirmed breach in any medium as soon as possible and no later than 1 hour of discovery, consistent with applicable CDC IT acquisitions guidance, HHS/CDC and incident management policy, and United States Computer Emergency Readiness Team (US-CERT) notification guidelines. To this end, the Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer

Security Incident Response Center (CSIRC) or CDC Computer Incident Response

Team (CSIRT) within 24 hours via email at csirt@cdc.gov or telephone at 866-655-

2245, whether the response is positive or negative.

5) All contractors and subcontractors shall be able to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector.

6) All contractors and subcontractors shall allow for an inspection, investigation, forensic analysis, and any other action necessary to ensure compliance with

HHS/CDC Policy and the HHS/CDC Breach Response Plan and to assist with responding to a breach.

7) Cloud service providers shall use…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .