SHEPheRD_Solicitation_POSTED_8.12.2011.doc

DOC document 432 KB Posted

Attached to
Safety and Healthcare Epidemiology Prevention Research Development (SHEPheRD) Program Federal contract opportunity
Solicitation number
2011-N-13526
Issued by
Department of Health and Human Services Centers for Disease Control and Prevention Office of Acquisition Services

About this file

To delete and replace L.11 Past Performance Information (Jan 2000) To include M.4 Past Performance Evaluation (Adjectival Rating System) (Jan 2000) To include in Section I Contract Clauses 52.216-27 Single or Multiple Awards (Oct 1995) To clarify proposal receipt time Standard Form 33 Block 9 2 00PM

View the file

Other files for this federal contract opportunity

Other files attached to Safety and Healthcare Epidemiology Prevention Research Development (SHEPheRD) Program, newest first.
File Type Posted
sf33_SHEPheRD.pdf PDF
Domain 1-Question Responses 8 10 11.doc DOC document
RFTOP.JZ.doc DOC document
RFTOP.JX.doc DOC document
SHEPheRD Solicitation POSTED 7.22.2011.doc DOC document
RFTOP.JY.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOLICITATION, OFFER AND AWARD

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

RATING

PAGE OF

2. CONTRACT NO.

3. SOLICITATION NO.

2011-N-13526

4. TYPE OF SOLICITATION

SEALED BID (IFB)

X

NEGOTIATED (RFP)

5. DATE ISSUED

07/22/2011

6. REQUISITION/PURCHASE NO.

7. ISSUED BY
CODE
2536
8. ADDRESS OFFER TO (If other than Item 7)

Centers for Disease Control and Prevention (CDC) Procurement and Grants Office (PGO) Acquisition and Assistance Branch 2 2920 Brandywine Road, MS K-14, Atlanta, GA 30341-5539

Approved as to Form and Legality: _____________________________

NOTE: In sealed bid solicitations “offer” and “offeror” mean “bid” and “bidder.”

SOLICITATION

9. Sealed offers in original and copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in address in block 7, mailroom 1110 until 2:00p local time 08/22/2011 CAUTION -- LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME

Linda Williams

B. TELEPHONE (NO COLLECT CALLS)

AREA CODE NUMBER: EXT:

(770) 488-2692

C. E-MAIL ADDRESS

11. TABLE OF CONTENTS

(x)

DESCRIPTION

(x)

DESCRIPTION

PART I – THE SCHEDULE
PART II – CONTRACT CLAUSES
X
A
SOLICITATION/CONTRACT FORM
1
X
I
CONTRACT CLAUSES
29
X
B
SUPPLIES OR SERVICES AND PRICES/COSTS
2
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
X
C
DESCRIPTION/SPECS./WORK STATEMENT
4
X
J
LIST OF ATTACHMENTS
37
X
D
PACKAGING AND MARKING
7
PART IV – REPRESENTATIONS AND INSTRUCTIONS
X
E
INSPECTION AND ACCEPTANCE
8

REPRESENTATIONS, CERTIFICATIONS, AND

X
F
DELIVERIES OR PERFORMANCE
9
X
K
OTHER STATEMENTS OF OFFERORS
38
X
G
CONTRACT ADMINISTRATION DATA
10
X
L
INSTRS., CONDS., AND NOTICES TO OFFERORS
48
X
H
SPECIAL CONTRACT REQUIREMENTS
13
X
M
EVALUATION FACTORS FOR AWARD
56

OFFER (Must be fully completed by offeror)

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52-232-8)

10 CALENDAR DAYS

20 CALENDAR DAYS

30 CALENDAR DAYS

AMENDMENT NO.
DATE
AMENDMENT NO.
DATE
CODE
FACILITY
16. NAME AND ADDRESS OF PERSON AUTHORIZED TO SIGN OFFER

15B. TELEPHONE NO.

AREA CODE NUMBER EXT.

15C. CHECK IF REMITTANCE ADDRESS

IS DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

17. SIGNATURE

18. OFFER DATE

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED

20. AMOUNT

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

21. ACCOUNTING AND APPROPRIATION

10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( )

23. SUBMIT INVOICES TO ADDRESS SHOWN IN

(4 copies unless otherwise specified)

ITEM

24. ADMINISTERED BY (If other than Item 7)
CODE
25. PAYMENT WILL BE MADE BY
CODE

26. NAME OF CONTRACTING OFFICER (Type or print)

27. UNITED STATES OF AMERICA

(Signature of Contracting Officer)

28. AWARD DATE

IMPORTANT -- Award will be made on this form, or on Standard Form 26, or by other authorized official written notice.

AUTHORIZED FOR LOCAL REPRODUCTION

STANDARD FORM 33 (REV. 9-97)

PREVIOUS EDITION IS UNUSABLE

Prescribed by GSA

FAR (48 CFR) 53.214©

Section B - Supplies Or Services And Prices/Costs

ITEM
SUPPLIES / SERVICES
QTY / UNIT
UNIT PRICE
EXTENDED PRICE
0001
Domain 1 HAI Prevention Implementation

Domain 1 Services for Healthcare Acquired Infection (HAI) Prevention Research Implementation in accordance with SOW. To be cited on individual Task Orders.

1 JOB
N/A
NTE$20,000,000.00

All pricing will be submitted with task order proposals

B.1 GENERAL

The purpose of this indefinite delivery, indefinite quantity (IDIQ) contract is to provide the Centers for Disease Control and Prevention (CDC), National Center for Emerging Zoonotic and Infectious Diseases (NCEZID), Division of Healthcare Quality Promotion (DHQP) an “as needed” mechanism to obtain required services through issuance of individual task orders in support of Healthcare-associated infections (HAI) prevention research studies that meet public health priorities for CDC. The awardees of the resultant contracts, independently and not as an agent of the United States Government, shall supply as necessary personnel, materials, transportation, supplies and equipment (except that specifically addressed within the individual task order) necessary to perform the individual Task Orders under the contract.

B.2 TASK ORDER CONTRACT

This Request For Proposal (RFP) will result in the award of an indefinite delivery, indefinite quantity (IDIQ) contract. Orders for services will be placed by individual Request for Task Order Proposals (RFTOPs) under this contract in accordance with Section C.4, Specific Contract Requirements and other applicable contract clauses.

The types and number of awards will be based on the government’s best value determinations (considering technical quality and proposed cost) of the proposals submitted. CDC is not imposing any restrictions on partnering, subcontracting, or proposal submissions related to exclusivity. Ordering under this contract will be conducted through task orders. RFTOPs will be competed among eligible contractors in the applicable work domain and business category unless an exception to competition is authorized by the Contracting Officer in accordance with Federal Acquisition Regulations (FAR) 16.505.

B.3 TYPE OF CONTRACT

This is a multiple award, IDIQ type contract. At the discretion of the Contracting Officer, the government may use a variety of task order types under this contract, including Firm Fixed Price(FFP), and cost types.

Each RFTOP issued under this contract will identify the Government’s determination of task order type.

B.4 MINIMUM GUARANTEE

The contract guarantees that task orders amount to a minimum of $1,000. In the event that during its contract term the contractor receives obligations of less than this minimum, the Government will fund the difference between the actual obligation and the guaranteed minimum.

B.5 MAXIMUM CONTRACT AMOUNT

The contract ceiling amount is $20,000,000.00

B.6 CONTRACT ADMINISTRATION

Please submit any and all questions in writing to Linda Williams at LWilliams6@cdc.gov. All questions must be submitted in writing by e-mail NLT Friday, July 29, 2011.

B.7 ADDITIONAL INFORMATION

See section L for important information as to what is required to be submitted in response to this request for proposal (RFP).

Section C - Description/Specification/Work Statement Title: Safety and Healthcare Epidemiology Prevention Research Development (SHEPheRD) Program C.1 Background and Need Healthcare-associated infections (HAIs) and other adverse events continue to cause significant morbidity and mortality among patients treated in healthcare institutions and add billions of dollars to healthcare costs in the United States. Additional Healthcare Epidemiology and Infection Control research is needed to facilitate development of innovative strategies for detection and prevention of HAIs, Antimicrobial Resistance (AR), and other adverse events in order to reduce the morbidity, mortality, and costs associated with these conditions. The Division of Healthcare Quality Promotion (DHQP) within the Centers for Disease Control and Prevention (CDC) has recently re-organized its HAI prevention research program to include multiple complementary initiatives. Currently titled the SHEPheRD Program, it is designed to maximize CDC’s ability to perform translational HAI prevention research. This indefinite delivery, indefinite quantity (IDIQ) contract is one component of this multifaceted research program. The SHEPheRD Program will eventually consist of four functional domains: 1) Research Implementation, 2) Research Development, 3) Program Assessment/Evaluation Studies and 4) Program Support Services. This contract will address only domain 1.

C.2 Project Identification and Purpose The purpose of this indefinite delivery, indefinite quantity (IDIQ) contract is to provide the Centers for Disease Control and Prevention (CDC) Division of Healthcare Quality Promotion (DHQP) an “as needed” mechanism to obtain required services through issuance of individual task orders in support of HAI prevention research studies that meet public health priorities for CDC. The scope of this contract is to provide scientific, technical, and management expertise, and related services involving research, planning, assessment, development, management, support, and execution of CDCs missions and activities.

C.3 Scope of Work The contractor shall, acting independently and not as an agent of the Government, provide all labor, supervision, equipment, materials, supplies, travel, transportation and perform all work necessary to provide public health practice, scientific, research and technical services in support of HAI prevention, as specifically outlined in individual task orders and this basic contract. The award of individual task orders will be made through a competitive process. The nature, scope, and complexity of the services to be performed will vary from task to task.

C.4 Specific Contract Requirements

1. Execute awarded task orders:

Task orders will provide services related to statistics, research design, research implementation, literature review and analysis, public health practice, surveillance, epidemiology, informatics, data management, data analysis, , , , performing data abstraction, providing scientific and technical support, preparation of IRB and OMB packages.

Domain One: HAI Prevention Research Implementation Contractors will provide services related to implementing single- and multi-center HAI prevention research studies in clinical settings, including but not limited to clinical or epidemiologic studies that inform HAI prevention strategy and studies that determine the efficacy or effectiveness of specific HAI prevention and surveillance strategies. Contractors should have direct access to large, multicenter networks of healthcare facilities, or access to large populations of insured patients. Services include:

Access to research populations. The Contractor will provide access to research populations either through networks of healthcare facilities or through insurance providers and managed care organizations that can provide data from large populations of insured patients. Contractors providing access to research populations through healthcare facilities may own, operate, or otherwise have access to large networks of healthcare facilities, that have a common information technology infrastructure that is currently being used to extract clinical and administrative data in a standardized format common to the facilities in the network, and can submit such data to a central location for storage and analysis. Contractors providing access to research populations through insurance providers and managed care organizations should have centralized access to administrative claims and other clinical data in standardized format and stored in a centralized location for analysis.

Recruitment. The Contractor will provide recruitment for healthcare facilities and patients within the network, where appropriate, to participate in HAI prevention research, including assessing the impact of infection control interventions.

Data. The Contractor will provided access to clinical and administrative data from a large population of patients or from a large number of healthcare institutions that collect data in a standardized common format.

IRB and OMB. Contractors will prepare and submit IRB and OMB packages, and oversee all aspects of implementation of clinical research studies pertaining to prevention of HAIs. The Contractor shall prepare the packages including all forms and attachments, for both local and CDC IRBs, for the Technical Monitor’s approval. The Contractor shall submit the IRB package to their IRB and shall ensure that all clinical sites involved in the study apply for and receive IRB approval.

Copies of IRB approvals from the Contractor and all clinical sites shall be provided to the Technical Monitor.

2.

Abide by the Award of Individual Task Orders Process.

Award of individual Task Orders will be made under competitive procedures as described Paragraph L9 Technical Proposal Instructions. The nature, scope, and complexity of the services to be performed will vary from task to task. Each Task Order will consist of a Statement of Work that will fall within the general work parameters described in the RFTOP.

3.

Key Personnel.

Shall provide oversight sufficient to address scientific issues related to individual Task Orders. Oversight includes all policy, program, evaluation design issues, assessment issues, and support services, which pertain to each new assigned task. Provide interface with the Contracting Officer’s Technical Representative and/or Contracting Officer and be responsible for the overall oversight of all work performed under the contract. This person will serve as the quality control point for all performance under the contract. This individual will be considered to be “key personnel” for the awarded contract.

C. 5 Tasks The SOW for each individual TO under this contract will define the support services required as areas, tasks, efforts, work assignments, or functions that are to be accomplished, under the general scope of this contract. The actual work will be authorized or "ordered" through the periodic issuance of individual TOs for services that fall within the general scope of this statement of work. Each TO will cite the appropriate section of the SOW and will provide a separate, detailed, and descriptive task order SOW of specific work required under that task order.

The service levels, delivery requirements, and periods of performance will be individually defined in each Task Order based on the type and complexity of work required. Deliverables will be identifiable in each individual task order and may include reports. If reports are required, the contractor shall prepare reports of the major accomplishments and activities completed during the previous month or other information as required by the task order SOW. The Contractor shall deliver any required reports to the COTR and Contracting Officer (CO) as required by the task order SOW.

Task 1: Start Up Meeting The Contractor shall arrange and conduct an initial meeting (either in person or by teleconference) with the COTR and other relevant staff within 2 weeks of the effective date of the task order. The purpose of the meeting will be to review and clarify the scope of work and delivery schedule for tasks, to delineate roles and responsibilities, and to establish communication protocols. Each task and deliverable will be reviewed.

Task 2: Maintain Communication with the COTR The Contractor shall coordinate with the COTR. The Contractor shall maintain regular communications with the COTR and CDC staff involved with the project. The chief means of communication will be via conference calls that will be scheduled every month throughout the project period required to complete the project. Additional calls will be scheduled as needed. The Contractor shall provide an agenda and meeting minutes for each call. All conference calls shall be scheduled and administered by the Contractor. The Contractor shall respond to all emails and telephone communications from the Project Officer within 2-3 working days.

Section D - Packaging And Marking

There are no clauses/provisions included in this section.

Section E - Inspection And Acceptance

FAR SOURCE
TITLE AND DATE

E.1 Inspection and Acceptance (Jul 1999)

Inspection and acceptance of the articles, services, and documentation called for herein shall be accomplished by the Contracting Officer, or his duly authorized representative (who for the purposes of this contract shall be the Contracting Officer’s Technical Representative ) at the destination of the articles, services or documentation.

(End of Clause) Section F - Deliveries Or Performance

FAR SOURCE
TITLE AND DATE
52.242-15
Stop-Work Order (Aug 1989)

F.1 Period of Performance

(a) Contract: The period of performance of this IDIQ contract shall be sixty (60) months. All Task Orders (TO) under this IDIQ shall be issued within the term of the contract and shall be completed within the time specified in each task order.

(b) Task Orders: The time for completion for each task or delivery order shall be determined under each individual task or delivery order through the mutual agreement of the parties involved. Task/delivery orders under this contract may be awarded by the Contracting Officer at any time within the contract period. The actual performance of the work may extend beyond the contract period.

(End of Clause)

F.2 Place(s) of Performance (Jul 1999)

The Contractor shall perform all work under this contract at Contractor’s facilities.

(End of Clause)

F.3 Deliverables Deliverables requirements will be as set forth in individual task orders.

(End of Clause) Section G - Contract Administration Data

G.1 Evaluation of Contractor Performance (Service) (Jan 2000)

(a) Purpose

In accordance with FAR 42.1502, the Contractor's performance will be periodically evaluated by the Government, in order to provide current information for source selection purposes. These evaluations will therefore be marked “Source Selection Information.”

(b) Performance Evaluation Period

The Contractor's performance will be evaluated at least annually.

(c) Evaluators The performance evaluation will be completed jointly by the Project officer and the Contracting officer.

(d) Performance Evaluation Factors The contractor's performance will be evaluated in accordance with the attachment listed in Section J titled Performance Evaluation Report.

(e) Contractor Review A copy of the evaluation will be provided to the contractor as soon as practicable after completion of the evaluation. The contractor shall submit comments, rebutting statements, or additional information to the Contracting Officer within 30 calendar days after receipt of the evaluation.

(f) Resolving Disagreements Between the Government and the Contractor Disagreements between the parties regarding the evaluation will be reviewed at a level above the Contracting Officer. The ultimate conclusion on the performance evaluation is a decision of the contracting agency. Copies of the evaluation, contractor's response, and review comments, if any, will be retained as part of the evaluation.

(g) Release of Contractor Performance Evaluation Information The completed evaluation will not be released to other than Government personnel and the contractor whose performance is being evaluated. Disclosure of such information could cause harm both to the commercial interest of the Government and to the competitive position of the contractor being evaluated as well as impede the efficiency of Government operations.

(h) Source Selection Information Departments and agencies may share past performance information with other Government departments and agencies when requested to support future award decisions. The information may be provided through interview and/or by sending the evaluation and comment document to the requesting source selection official.

(i) Retention Period The agency will retain past performance information for a maximum period of three years after completion of contract performance for the purpose of providing source selection information for future contract awards.

(End of Clause)

G.2 Payment by Electronic Funds Transfer (Dec 2005) (Dec 2005)

(a) The Government shall use electronic funds transfer to the maximum extent possible when making payments under this contract. FAR 52.232-33, Payment by Electronic Funds Transfer – Central Contractor Registration, in Section I, requires the contractor to designate in writing a financial institution for receipt of electronic funds transfer payments.

(b) In addition to Central Contractor Registration, the contractor shall make the designation by submitting the form titled “ACH Vendor/Miscellaneous Payment Enrollment Form” to the address indicated below. Note: The form is either attached to this contract (see Section J, List of Attachments) or may be obtained by contacting the Contracting Officer or the CDC Financial Management Office at (404) 498-4050.

(c) In cases where the contractor has previously provided such designation, i.e., pursuant to a prior contract/order, and been enrolled in the program, the form is not required unless the designated financial institution has changed.

(d) The completed form shall be mailed after award, but no later than 14 calendar days before an invoice is submitted, to the following address:

The Centers for Disease Control and Prevention Financial Management Office (FMO) P.O. Box 15580 Atlanta, GA 30333 Or – Fax copy to: 404-638-5342 (End of Clause)

G.3 Electronic Subcontracting Reporting System (eSRS) (Dec 2005)

The contractor shall register with the Electronic Subcontracts Reporting System (eSRS) for the submission of its Individual Subcontract Report (SF 294) and the Annual Summary Reports (SF 295). Before registering in eSRS, the contractor information must be correct in Central Contractor Registration database. The eSRS is a world wide web-based application available at: http://www.esrs.gov. The eSRS website provides training and instruction for data submission.

(End of Clause)

G.4 Invoice Submission

(a) The Contractor shall submit the original contract invoice/voucher to the shown below:

The Centers for Disease Control and Prevention Financial Management Office (FMO) P.O. Box 15580 Atlanta, GA 30333 Or – The Contractor may submit the original invoice/voucher via facsimile or email:

Fax: 404-638-5324 Email: FMOAPINV@CDC.GOV NOTE: Submit to only one (1) of the above locations.

(b) The contractor shall submit 1 copy of the invoice/voucher to the cognizant contracting office previously identified in this contract. These invoices/voucher copies shall be addressed to the attention of the Contracting Officer. LWilliams6@cdc.gov

(c) The Contractor is required to submit a copy of each invoice directly to the Project Officer concurrently with submission to the Contracting Officer. KRAnderson@cdc.gov

(d) In accordance with 5 CFR part 1315 (Prompt Payment), CDC's Financial Management Office is the designated billing office for the purpose of determining the payment due date under FAR 32.904.

(e) The Contractor shall include (as a minimum) the following information on each invoice:

(1) Contractor’s Name & Address

(2) Contractor’s Tax Identification Number (TIN)

(3) Purchase Order/Contract Number and Task Order Number, if Appropriate

(4) Invoice Number

(5) Invoice Date

(6) Contract Line Item Number and Description of Item

(7) Quantity

(8) Unit Price & Extended Amount for each line item

(9) Shipping and Payment Terms

(10) Total Amount of Invoice

(11) Name, title and telephone number of person to be notified in the event of a defective invoice.

(12) Payment Address, if different from the information in (c)(1).

(13) DUNS + 4 Number (End of Clause) Section H - Special Contract Requirements

FAR SOURCE
TITLE AND DATE
CDCA.H037
Observance of Legal Holidays and Administrative Leave (Government Facilities Performance) (Feb 2011)

H.1 FAR CDC0.H019 Security Clearances (Sep 2009)

CDC0_H019 Security Clearances

(a) Definitions.

“Employees” means both contractor and subcontractor employees unless otherwise noted:

The phrase “CDC owned or leased facilities” includes ATSDR, NIOSH/PRC/Pittsburgh, Pa.; NIOSH/Morgantown, W.V.; NIOSH/SRC/Spokane, WA; NIOSH/Cincinnati, OH; NCHS/Research Triangle Park, NC; NCHS/Hyattsville, MD, NCID/Fort Collins, CO; NCID/Anchorage, AK, and NCID/San Juan, PR.

(b) General All contract employees who will be performing work under this contract on-site (i.e., in a CDC owned or leased facility) for a period exceeding 90 days in duration (45 days if employee is designated to work in Building 10, 15, or 17 at 1600 Clifton Road, Atlanta, GA, or at CDC’s Lawrenceville, GA facility) shall receive a favorable suitability determination prior to reporting to work at an on-site facility. Any contract employee(s) who cannot obtain a favorable suitability determination will not be permitted to work at an on-site facility (see paragraph B below on temporary determinations.)

The Contractor shall be responsible for managing its workforce to ensure that sufficient contract employees who meet all suitability requirements are available to perform the duties required under the contract. New or replacement contract employees must have previously received a favorable suitability determination in sufficient time to perform work at an on-site facility under the contract. If it has been over one (1) year since a contract employee has worked in a position on a Federal contract for which a security clearance was required, a new National Agency Check and Inquiry (NACI) must be obtained.

(c) Temporary Determinations/Clearances The Contracting Officer may, as appropriate, authorize and grant temporary suitability determinations to contract employees. However, the granting of a temporary determination shall not be considered as assurance that full clearance will follow. The granting of a temporary determination shall not prevent, preclude or bar the withdrawal or termination of any temporary determination. Prior to the Government's issuance of a temporary determination, the Contractor shall obtain and provide to the Contracting Officer a state-wide criminal records check for all on-site contract employees. The Contractor shall also obtain and provide to the Contracting Officer a state-wide motor vehicle violations check for any contract employee required to operate a motor vehicle as part of their duties under the contract at an on-site facility. All criminal record checks and motor vehicle violation checks shall cover a twelve (12) month period beginning twelve (12) months prior to the date of the contract award. Criminal record checks and motor vehicle violation checks may be obtained through local state, county or city law enforcement agencies at contract employees’ place of residence. Where state-wide criminal record and motor vehicle violation systems are not available, county-wide or city-wide checks may be substituted. All substitutions shall be certified by the law enforcement agency that a state-wide criminal record system is not available.

(d) Required Information for NACI Clearance:

Unless otherwise specified, the Contractor shall submit the completed forms specified below to the appropriate office as directed by the Contracting Officer not later then 5 calendar days from the effective date of the contract. Items (1) through (6) must be completed by contract employees who require access to on-site facilities in the performance of the contract. Additionally, the contractor shall furnish, on a monthly basis, item (7) (if the information requested in Item (7) is provided as part of the Contractor’s standard invoice, no additional submission is required). The Government will furnish the necessary forms to the Contractor.

(1) Two (2) completed Forms FD-258, "FBI Fingerprint Charts"***

(2) One (1) completed Standard Form 85, "Questionnaire for Non-Sensitive Positions"

(3) One (1) completed "Declaration for Enrollment"

(4) One (1) resume or curriculum vitae or completed job application form

(5) One (1) copy of the state-wide criminal records check

(6) One (1) copy of the motor vehicle violations check (when applicable)

(7) A complete listing of all current Contractor and Subcontractor on-site employees by name, work location and employer.

The CDC, Human Resource Management Offices (HRMO) have the necessary equipment to complete fingerprint charts (FD-258). The Contractor may contact the Contracting Officer for arrangements regarding utilization of the HRMO fingerprinting equipment. The fingerprint charts may also be completed through a local state, county or city law enforcement agency at the employee's place of residence.

Using the required information specified above, a National Agency Check and Inquiry (NACI) will be processed by the CDC through the Office of Personnel Management and the Federal Bureau of Investigations (OPM/FBI) on each contract employee who will be performing duties on-site.

(d) Removal of Contractor Employees The Contracting Officer may request the Contractor to immediately remove any contract employee from the on-site facility who has failed to receive a suitability determination and whose continued employment is deemed contrary to the public interest, inconsistent with the best interests of security, or is identified as a potential threat to the health, safety, security, general well being or operational mission of the on-site facility and its population. The Contracting Officer may also request the Contractor to immediately remove any contract employee from the on-site facility should it be determined that the individuals are being assigned to duty who have been disqualified for suitability reasons, or who are found to be unfit for performing duties during their tour(s) of duty. Contract employees who are requested to be removed from the on-site facility are required to leave the work site immediately.

The Contracting Officer will make all determinations regarding the removal of any contract employee from the on-site facility, except under certain conditions. When a Contracting Officer is not available, either during the day or after normal business hours, or in situations where a delay would not be in the best interest of the Government, or a potential threat to the health, safety, security, general well being or operational mission of the facility and its population, the Project Officer will have the authority to direct immediate removal of the contractor employee from the on-site facility. The Contracting Officer shall subsequently provide the official notification to the Contractor for removal of a contract employee from the CDC facility. When removal is directed due to a non-suitability determination as a result of the NACI, no further information will be provided. If removal is directed for other reasons relating to specific conduct of the employee during performance of the work, the Contracting Officer’s official notification will provide information as to these reasons.

(e) Identification Badges/Cardkey Access:

(1) Identification Badges:

The Contractor shall require each contract employee who has been authorized unescorted access to an on-site facility, either through the temporary clearance process or the formal NACI process, to display an identification badge as required and furnished by the CDC. The Contractor shall submit to the Project Officer a completed Identification Badge Request Form (CDC Form 0.1137) for each contract employee who has been authorized unescorted access to an on-site facility. Contact the Project Officer for details on additional procedures, specific addresses and hours of business for issuance of Identification Badges for all other CDC locations.

(2) Cardkey Access:

Unescorted access to certain on-site facilities at CDC may only be gained through the use of a Cardkey. If a contract employee has been determined to need regular unescorted access to one of the Cardkey access designated areas, a Cardkey Request Form (CDC Form 0.834) must be completed and submitted to the Project Officer for written approval. Contact the Project Officer for details of procedures and specific addresses and hours of business for issuance of Cardkey Access.

(3) Return of Identification Badges/Cardkeys The Contractor shall arrange for the return of any employee identification badges and/or cardkeys immediately upon their separation of the duties at the on-site facility. Contact the Project Officer for location of the depositories for the return of badges. Cardkeys shall be returned to the appropriate Physical Security Activity Office.

(End of Clause)

H.2 HHSAR 352.239-70 Standard for Security Configurations (Oct 2009)

(a) The Contractor shall configure its computers that contain HHS data with the applicable Federal Desktop Core Configuration (FDCC) (see http://nvd.nist.gov/fdcc/index.cfm) and ensure that its computers have and maintain the latest operating system patch level and anti-virus software level.

Note: FDCC is applicable to all computing systems using Windows XPTM and Windows VistaTM, including desktops and laptops--regardless of function--but not including servers.

(b) The Contractor shall apply approved security configurations to information technology (IT) that is used to process information on behalf of HHS. The following security configuration requirements apply:

Approved security configurations are identified in NIST checklists (http://web.nvd.nist.gov/view/ncp/repository) or contained in a DoD DISA security technical implementation guide or security checklist http://iase.disa.mil/stigs/index.html. If CDC specific security configuration requirements are later determined to apply, they will be provided subsequent to contract award and incorporated by contract modification.

Note: The Contracting Officer shall specify applicable security configuration requirements in solicitations and contracts based on information provided by the Project Officer, who shall consult with the OPDIV/STAFFDIV Chief Information Security Officer.

(c) The Contractor shall ensure IT applications operated on behalf of HHS are fully functional and operate correctly on systems configured in accordance with the above configuration requirements. The Contractor shall use Security Content Automation Protocol (SCAP)-validated tools with FDCC Scanner capability to ensure its products operate correctly with FDCC configurations and do not alter FDCC settings--see http://nvd.nist.gov/validation.cfm. The Contractor shall test applicable product versions with all relevant and current updates and patches installed. The Contractor shall ensure currently supported versions of information technology products meet the latest FDCC major version and subsequent major versions.

(d) The Contractor shall ensure IT applications designed for end users run in the standard user context without requiring elevated administrative privileges.

(e) The Contractor shall ensure hardware and software installation, operation, maintenance, update, and patching will not alter the configuration settings or requirements specified above.

(f) The Contractor shall (1) include Federal Information Processing Standard (FIPS) 201-compliant (see http://csrc.nist.gov/publications/fips/fips201-1/FIPS-201-1-chng1.pdf), Homeland Security Presidential Directive 12 (HSPD-12) card readers with the purchase of servers, desktops, and laptops; and (2) comply with FAR Subpart 4.13, Personal Identity Verification.

(g) The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.

(End of clause)

H.3 HHSAR 352.239-71 Standard for Encryption Language (Oct 2009)

(a) The Contractor shall use Federal Information Processing Standard (FIPS) 140-2-compliant encryption (Security Requirements for Cryptographic Module, as amended) to protect all instances of HHS sensitive information during storage and transmission. (Note: The Government has determined that HHS information under this contract is considered ``sensitive'' in accordance with FIPS 199, Standards for Security Categorization of Federal Information and Information Systems, dated February 2004.)

(b) The Contractor shall verify that the selected encryption product has been validated under the Cryptographic Module Validation Program (see http://csrc.nist.gov/cryptval/) to confirm compliance with FIPS 140-2 (as amended). The Contractor shall provide a written copy of the validation documentation to the Contracting Officer and the Contracting Officer's Technical Representative.

(c) The Contractor shall use the Key Management Key (see FIPS 201, Chapter 4, as amended) on the HHS personal identification verification (PIV) card; or alternatively, the Contractor shall establish and use a key recovery mechanism to ensure the ability for authorized personnel to decrypt and recover all encrypted information (see http://csrc.nist.gov/drivers/documents/ombencryption-guidance.pdf). The Contractor shall notify the Contracting Officer and the Contracting Officer's Technical Representative of personnel authorized to decrypt and recover all encrypted information.

(d) The Contractor shall securely generate and manage encryption keys to prevent unauthorized decryption of information in accordance with FIPS 140-2 (as amended).

(e) The Contractor shall ensure that this standard is incorporated into the Contractor's property management/control system or establish a separate procedure to account for all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive HHS information.

(f) The Contractor shall ensure that its subcontractors (at all tiers) which perform work under this contract comply with the requirements contained in this clause.

(End of clause)

H.4 HHSAR 352.239-72 Security Requirements for Federal Information Technology Resources (Oct 2009)

(a) Applicability. This clause applies whether the entire contract or order (hereafter ``contract''), or portion thereof, includes information technology resources or services in which the Contractor has physical or logical (electronic) access to, or operates a Department of Health and Human Services (HHS) system containing, information that directly supports HHS' mission. The term ``information technology (IT)'', as used in this clause, includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services) and related resources. This clause does not apply to national security systems as defined in FISMA.

(b) Contractor responsibilities. The Contractor is responsible for the following:

(1) Protecting Federal information and Federal information systems in order to ensure their--

(i) Integrity, which means guarding against improper information modification or destruction, and includes ensuring information non-repudiation and authenticity;

(ii) Confidentiality, which means preserving authorized restrictions on access and disclosure, including means for protecting personal privacy and proprietary information; and.

(iii) Availability, which means ensuring timely and reliable access to and use of information.

(2) Providing security of any Contractor systems, and information contained therein, connected to an HHS network or operated by the Contractor, regardless of location, on behalf of HHS.

(3) Adopting, and implementing, at a minimum, the policies, procedures, controls, and standards of the HHS Information Security Program to ensure the integrity, confidentiality, and availability of Federal information and Federal information systems for which the Contractor is responsible under this contract or to which it may otherwise have access under this contract. The HHS Information Security Program is outlined in the HHS Information Security Program Policy, which is available on the HHS Office of the Chief Information Officer's (OCIO) Web site.

(c) Contractor security deliverables. In accordance with the timeframes specified, the Contractor shall prepare and submit the following security documents to the Contracting Officer for review, comment, and acceptance:

(1) IT Security Plan (IT-SP)--due within 30 days after contract award. The IT-SP shall be consistent with, and further detail the approach to, IT security contained in the Contractor's bid or proposal that resulted in the award of this contract. The IT-SP shall describe the processes and procedures that the Contractor will follow to ensure appropriate security of IT resources that are developed, processed, or used under this contract. If the IT-SP only applies to a portion of the contract, the Contractor shall specify those parts of the contract to which the IT-SP applies.

(i) The Contractor's IT-SP shall comply with applicable Federal laws that include, but are not limited to, the Federal Information Security Management Act (FISMA) of 2002 (Title III of the E-Government Act of 2002, Public Law 107-347), and the following Federal and HHS policies and procedures:

(A) Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources, Appendix III, Security of Federal Automated Information Resources.

(B) National Institute of Standards and Technology (NIST) Special Publication (SP) 800-18, Guide for Developing Security Plans for Federal Information Systems, in form and content, and with any pertinent contract Statement of Work/Performance Work Statement (SOW/PWS) requirements. The IT-SP shall identify and document appropriate IT security controls consistent with the sensitivity of the information and the requirements of Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems. The Contractor shall review and update the IT-SP in accordance with NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems and FIPS 200, on an annual basis.

(C) HHS-OCIO Information Systems Security and Privacy Policy.

(ii) After resolution of any comments provided by the Government on the draft IT-SP, the Contracting Officer shall accept the IT-SP and incorporate the Contractor's final version into the contract for Contractor implementation and maintenance. On an annual basis, the Contractor shall provide to the Contracting Officer verification that the IT-SP remains valid.

(2) IT Risk Assessment (IT-RA)--due within 30 days after contract award. The IT-RA shall be consistent, in form and content, with NIST SP 800-30, Risk Management Guide for Information Technology Systems, and any additions or augmentations described in the HHS-OCIO Information Systems Security and Privacy Policy. After resolution of any comments provided by the Government on the draft IT-RA, the Contracting Officer shall accept the IT-RA and incorporate the Contractor's final version into the contract for Contractor implementation and maintenance. The Contractor shall update the IT-RA on an annual basis.

(3) FIPS 199 Standards for Security Categorization of Federal Information and Information Systems Assessment (FIPS 199 Assessment)--due within 30 days after contract award. The FIPS 199 Assessment shall be consistent with the cited NIST standard. After resolution of any comments by the Government on the draft FIPS 199 Assessment, the Contracting Officer shall accept the FIPS 199 Assessment and incorporate the Contractor's final version into the contract.

(4) IT Security Certification and Accreditation (IT-SC&A)--due within 3 months after contract award. The Contractor shall submit written proof to the Contracting Officer that an IT-SC&A was performed for applicable information systems--see paragraph (a) of this clause. The Contractor shall perform the IT-SC&A in accordance with the HHS Chief Information Security Officer's Certification and Accreditation Checklist; NIST SP 800-37, Guide for the Security Certification and Accreditation of Federal Information Systems; and NIST SP 800-53, Recommended Security Controls for Federal Information Systems. An authorized senior management official shall sign the draft IT-SC&A and provide it to the Contracting Officer for review, comment, and acceptance.

(i) After resolution of any comments provided by the Government on the draft IT-SC&A, the Contracting Officer shall accept the IT-SC&A and incorporate the Contractor's final version into the contract as a compliance requirement.

(ii) The Contractor shall also perform an annual security control assessment and provide to the Contracting Officer verification that the IT-SC&A remains valid. Evidence of a valid system accreditation includes written results of:

(A) Annual testing of the system contingency plan; and

(B) The performance of security control testing and evaluation.

(d) Personal identity verification. The Contractor shall identify its employees with access to systems operated by the Contractor for HHS or connected to HHS systems and networks. The Contracting Officer's Technical Representative (COTR) shall identify, for those identified employees, position sensitivity levels that are commensurate with the responsibilities and risks associated with their assigned positions. The Contractor shall comply with the HSPD-12 requirements contained in ``HHS-Controlled Facilities and Information Systems Security'' requirements specified in the SOW/PWS of this contract.

(e) Contractor and subcontractor employee training. The Contractor shall ensure that its employees, and those of its subcontractors, performing under this contract complete HHS-furnished initial and refresher security and privacy education and awareness training before being granted access to systems operated by the Contractor on behalf of HHS or access to HHS systems and networks. The Contractor shall provide documentation to the COTR evidencing that Contractor employees have completed the required training.

(f) Government access for IT inspection. The Contractor shall afford the Government access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in performance of this contract to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the integrity, confidentiality, and availability, of HHS data or to the protection of information systems operated on behalf of HHS.

(g) Subcontracts. The Contractor shall incorporate the substance of this clause in all subcontracts that require protection of Federal information and Federal information systems as described in paragraph (a) of this clause, including those subcontracts that--

(1) Have physical or electronic access to HHS' computer systems, networks, or IT infrastructure; or

(2) Use information systems to generate, store, process, or exchange data with HHS or on behalf of HHS, regardless of whether the data resides on a HHS or the Contractor's information system.

(h) Contractor employment notice. The Contractor shall immediately notify the Contracting Officer when an employee either begins or terminates employment (or is no longer assigned to the HHS project under this contract), if that employee has, or had, access to HHS information systems or data.

(i) Document information. The Contractor shall contact the Contracting Officer for any documents, information, or forms necessary to comply with the requirements of this clause.

(j) Contractor responsibilities upon physical completion of the contract. The Contractor shall return all HHS information and IT resources provided to the Contractor during contract performance and certify that all HHS information has been purged from Contractor-owned systems used in contract performance.

(k) Failure to comply. Failure on the part of the Contractor or its subcontractors to comply with the terms of this clause shall be grounds for the Contracting Officer to terminate this contract.

(End of clause)

H.5 Data Subject to Confidentiality Requirements (May 1998)

The type(s) of data subject to the clause at 352.224-70, Confidentiality of Information, which has been incorporated by reference in Section I, are as follows:

Following are the requirements for handling these data:

H.6 Special Provisions (Sep 2009)

CDC0_H043 Special Provisions

Some or all of the following special provisions are applicable only to the extent indicated in individual task orders:

Data Collection Approval Privacy Act HHSAR 352.280-1(b), Protection of Human Subjects PHSAR 352.280-2(b), Care of Live Vertebrate Animals Printing Restrictions Inclusion of Women and Racial and Ethnic Minorities in Research Automated Information Systems (AIS) Security Contractor Security Requirements

HIPAA

HSPD-12

Section 508 (End of Clause)

H.7 Privacy Act (Sep 2009)

CDC0_H045 Privacy Act

(a) Notification is hereby given that the Contractor and its employees are subject to criminal penalties for violation of the Privacy Act to the same extent as employees of the Government. The Contractor shall assure that each of its employees knows the prescribed rules of conduct and that each is aware that he or she can be subjected to criminal penalty for violation of the Act. A copy of 45 CFR Part 5b, Privacy Act Regulations, may be obtained at http://ecfr.gpoaccess.gov/cgi/t/text/text-idx?c=ecfr&tpl=%2Findex.tpl.

(b) The Project Officer is hereby designated as the official who is responsible for monitoring contractor compliance with the Privacy Act.

(c) The Contractor shall follow the Privacy Act guidance as contained in the Privacy Act system notice provided in Section J, List of Attachments.

(End of Clause)

H.8 Agency Ombudsman (Sep 2009)

CDC0_H046 Agency Ombudsman CDC is committed to ensuring fair opportunity for all offerors submitting proposals for competitive task/delivery orders issued against existing contracts in accordance with FAR 16.505. Offerors/Contractors may protest task/delivery order awards of any amount on the grounds that the order increases the scope, period, or maximum value of the contract under which the order was issued. These complaints may be lodged at the agency level or protested with the General Accountability Office (GAO).

Additionally, in accordance with 41 U.S.C. 253(j), protests of task/delivery orders valued in excess of…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .